{"name":"Cloud ASN Risk Watchlist","snapshot":"2026-10-09","generated":"2026-10-09","license":"CC BY 4.0","source":"https://blog.infostruction.com/research/cloud-asn-risk-watchlist/","internal_columns_removed":["Local Notes","Local Override"],"counts":{"Catalog ASNs":1151,"Enabled for monitoring":559,"T1 Critical":403,"T2 High":60,"T3 Context":107,"T4 Review":581,"On Spamhaus ASN-DROP":431,"Published indicators":511,"Detection patterns":29,"Cited sources":159,"Holder countries represented":82,"Review-only rows":592},"asn_catalog":[{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS245","ASN Number":"245","Network Name":"PRC-AS - Planning Research Corporation","Aliases":"planningresearchcorp.com; PRC-AS","Provider Family":"planningresearchcorp.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2026-02-06","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"205","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as PRC-AS (planningresearchcorp.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS2601","ASN Number":"2601","Network Name":"RADIOLINK-AS Pitline Ltd","Aliases":"Pitline Ltd; RADIOLINK-AS","Provider Family":"pitline.net","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"70","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as RADIOLINK-AS (pitline.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"UA:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS2702","ASN Number":"2702","Network Name":"INTERSERVE - Novx Systems, Inc","Aliases":"novx-systems; INTERSERVE","Provider Family":"novx-systems","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2026-04-29","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"206","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as INTERSERVE (novx-systems).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS3507","ASN Number":"3507","Network Name":"IPSWAT TEAM - IPSwat LLC","Aliases":"IPSwat LLC; IPSWAT_TEAM","Provider Family":"ipswat.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"167","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as IPSWAT_TEAM (ipswat.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS3563","ASN Number":"3563","Network Name":"PILOT-ASN - Pilot Network Services, Inc","Aliases":"pilot.net; PILOT-ASN","Provider Family":"pilot.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2026-03-16","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"207","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as PILOT-ASN (pilot.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS5065","ASN Number":"5065","Network Name":"BUNNY-COMMUNICATIONS-GLOBAL - Bunny Communications","Aliases":"Bunny Communications; BUNNY-COMMUNICATIONS-GLOBAL","Provider Family":"bunnycommunications.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"18","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BUNNY-COMMUNICATIONS-GLOBAL (bunnycommunications.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"2","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"2","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BD:1, HK:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS6186","ASN Number":"6186","Network Name":"GARCIA-ASN - Garcia Consulting, Inc.","Aliases":"mylir.co.uk; GARCIA-ASN","Provider Family":"mylir.co.uk","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2026-02-06","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"209","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as GARCIA-ASN (mylir.co.uk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS6207","ASN Number":"6207","Network Name":"BUNNY-COMMUNICATIONS - Bunny Communications","Aliases":"bunnycommunications.com; BUNNY-COMMUNICATIONS","Provider Family":"bunnycommunications.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"210","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BUNNY-COMMUNICATIONS (bunnycommunications.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS6729","ASN Number":"6729","Network Name":"DEMENIN-AS DEMENIN B.V.","Aliases":"Bignet; bignet.ua; DEMENIN-AS; DEMENIN B.V.","Provider Family":"bignet.ua","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting/transit infrastructure","Category":"Current Spamhaus ASN-DROP","Evidence Level":"Strong","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"211","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS6729 is active and in the live Spamhaus ASN-DROP feed under the bignet.ua operator label. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DEMENIN-AS (bignet.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current active ASN-DROP membership supports aggressive control with daily refresh.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS7857","ASN Number":"7857","Network Name":"EMPIRE2-ASN - Empire Communications, Inc.","Aliases":"empire-communications; EMPIRE2-ASN","Provider Family":"empire-communications","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2026-04-29","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"213","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as EMPIRE2-ASN (empire-communications).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS8129","ASN Number":"8129","Network Name":"CAIWIRELESS - CAI Wireless Systems, Inc.","Aliases":"caiwireless.net; CAIWIRELESS","Provider Family":"caiwireless.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2026-05-06","Network Type":"ISP / network operator","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"215","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CAIWIRELESS (caiwireless.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS8649","ASN Number":"8649","Network Name":"Webtraffic ZeXoTeK IT-Services GmbH","Aliases":"ZeXoTeK IT-Services GmbH; Webtraffic","Provider Family":"zexotek.de","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"216","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Webtraffic (zexotek.de).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS9164","ASN Number":"9164","Network Name":"R-TEL-AS \"R-TEL\" LLC","Aliases":"R-TEL; Bignet; bignet.ua; R-TEL-AS; R-TEL LLC; R-TEL-AS R-TEL LLC","Provider Family":"bignet.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"ISP, transit and hosting infrastructure","Category":"Current Spamhaus ASN-DROP","Evidence Level":"Strong","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"217","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-02","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS9164 is active and in the live Spamhaus ASN-DROP feed under the bignet.ua operator label. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as R-TEL-AS (bignet.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current active ASN-DROP membership supports blocking while listed. Routing re-verified 2026-10-02: origination resumed after the dormant period recorded in the previous snapshot. RIR object remains active. ASN-DROP membership unchanged, so tier and enablement are unchanged.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS11527","ASN Number":"11527","Network Name":"X0R - Xproxies","Aliases":"Xproxies; NOVABROADBAND","Provider Family":"xproxies.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"ISP / network operator","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"218","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NOVABROADBAND (xproxies.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS13875","ASN Number":"13875","Network Name":"AS13875-MX-FIBER - MxFiber LLC","Aliases":"MxFiber LLC","Provider Family":"mxfiber.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"ISP / network operator","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"198","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AS13875-MX-FIBER (mxfiber.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS14576","ASN Number":"14576","Network Name":"HOSTING-SOLUTIONS - Hosting Solution Ltd.","Aliases":"Hosting Solution Ltd.; HOSTING-SOLUTIONS","Provider Family":"king-servers.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"95","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as HOSTING-SOLUTIONS (king-servers.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"8","IPsum IPs":"5","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"4","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"US:6, NL:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS17612","ASN Number":"17612","Network Name":"RINNAI-AS-KR-KR - Rinnai Korea","Aliases":"Rinnai Korea; RINNAI-AS-KR","Provider Family":"rinnai.co.kr","RIR Country Code":"KR","Country Name":"South Korea","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"220","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as RINNAI-AS-KR (rinnai.co.kr).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS18526","ASN Number":"18526","Network Name":"DDPS - DDPS Networks, LLC","Aliases":"DDPS Networks, LLC; DDPS","Provider Family":"ddps.jp","RIR Country Code":"JP","Country Name":"Japan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"34","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DDPS (ddps.jp).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"2","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"JP:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS23865","ASN Number":"23865","Network Name":"NETINNOVATIONLLC-AS-AP - Net Innovation LLC","Aliases":"Net Innovation; netinnovation.net; NETINNOVATIONLLC-AS-AP; net innovation llc","Provider Family":"netinnovation.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting/transit infrastructure","Category":"Current Spamhaus ASN-DROP","Evidence Level":"Strong","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"222","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS23865 is active and in live Spamhaus ASN-DROP under netinnovation.net, with Spamhaus country mapping JP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NETINNOVATIONLLC-AS-AP (netinnovation.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current active ASN-DROP membership supports blocking while listed.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS24544","ASN Number":"24544","Network Name":"LAWSCLOUDINFRASTRUCTURELIMITED-AS-HK - Law's Cloud Infrastructure Limited","Aliases":"Law's Cloud Infrastructure Limited; LAWSCLOUDINFRASTRUCTURELIMITED-AS-HK","Provider Family":"cloudie.hk","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"62","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as LAWSCLOUDINFRASTRUCTURELIMITED-AS-HK (cloudie.hk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"14","IPsum IPs":"12","IPsum Score >=3":"5","IPsum Score >=5":"3","Open-Proxy IPs":"0","Data-Shield IPs":"9","Talos 2024 IPs":"0","Multi-list IPs":"7","Listed-IP Country Mix":"HK:14"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS25288","ASN Number":"25288","Network Name":"LIR-UKRAINE-AS DEMENIN B.V.","Aliases":"Bignet; bignet.ua; LIR-UKRAINE; LIR-UKRAINE-AS; DEMENIN B.V.","Provider Family":"bignet.ua","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting/transit infrastructure","Category":"Current Spamhaus ASN-DROP","Evidence Level":"Strong","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"194","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS25288 is active and in live Spamhaus ASN-DROP under bignet.ua. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as LIR-UKRAINE-AS (bignet.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current active ASN-DROP membership supports blocking while listed.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS25862","ASN Number":"25862","Network Name":"ISNX - ISNX LLC","Aliases":"ISNX LLC; ISNX","Provider Family":"cloudie.hk","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"225","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ISNX (cloudie.hk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS26132","ASN Number":"26132","Network Name":"DDPS - DDPS Networks, LLC","Aliases":"ddps.jp; DDPS","Provider Family":"ddps.jp","RIR Country Code":"JP","Country Name":"Japan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2024-11-22","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"226","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DDPS (ddps.jp).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS26173","ASN Number":"26173","Network Name":"AS26173 - King's Cross N.V.","Aliases":"wirelesscuracao.com; King's_Cross_N.V.","Provider Family":"wirelesscuracao.com","RIR Country Code":"CW","Country Name":"Curaçao","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-03-10","Network Type":"ISP / network operator","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"227","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as King's_Cross_N.V. (wirelesscuracao.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS26833","ASN Number":"26833","Network Name":"ETCC - Electronic Transaction Consultants Corporation","Aliases":"Electronic Transaction Consultants Corpo; ETCC","Provider Family":"quarterhill.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2026-06-16","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"229","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ETCC (quarterhill.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS31561","ASN Number":"31561","Network Name":"NINE-IX MOJI SAS","Aliases":"pitline.net; NINE-IX","Provider Family":"pitline.net","RIR Country Code":"FR","Country Name":"France","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2018-09-25","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"231","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NINE-IX (pitline.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS33042","ASN Number":"33042","Network Name":"NETIFACE-TORONTO - Netiface LLC","Aliases":"Netiface LLC; NETIFACE-TORONTO","Provider Family":"netiface.co.uk","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"232","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NETIFACE-TORONTO (netiface.co.uk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS33993","ASN Number":"33993","Network Name":"UFO-AS UFO Hosting LLC","Aliases":"UFO Hosting; Stark successor; PQ.Hosting successor; UFO-AS; Stark Industries Solutions; stark-industries.solutions; UFO Hosting LLC (Russia); UFO Hosting LLC","Provider Family":"Stark / PQ.Hosting / THE.Hosting / UFO","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Bulletproof / high-risk hosting family","Category":"Sanctioned threat-activity-enabler successor (active)","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"13","Login / Identity Evidence":"No","Actor / Campaign":"Russian state-sponsored operations; Iranian state-sponsored operations; DPRK operations; Chinese state-sponsored operations; Doppelgänger; cybercrime infrastructure","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, S12, S13, N01, S03","Evidence Summary":"Recorded Future assessed with high confidence that UFO Hosting/AS33993 was established or repurposed as a sanctions-resilient vehicle for Stark Industries/PQ.Hosting infrastructure after the EU designation. The current Spamhaus ASN-DROP feed identifies its domain as stark-industries.solutions. AS33993 is active and in live Spamhaus ASN-DROP, mapped by Spamhaus to Stark Industries Solutions. Research tracks AS44477 through PQ.Hosting/THE.Hosting changes, creation of AS209847 and Russian infrastructure migration to AS33993. AS209847 and AS33993 are in current ASN-DROP; AS44477 is currently unannounced. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as UFO-AS (stark-industries.solutions).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current active ASN-DROP membership supports aggressive control while listed. High for successor/control relationship and threat-actor-enabler status; label is TAE rather than asserting that every customer is malicious. Active and announcing routes as UFO Hosting LLC on 2026-09-15; present in the current Spamhaus ASN-DROP snapshot.","Current Community Feed Count":"2","Current Listed IPs":"10","IPsum IPs":"6","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"5","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"RU:10"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS34450","ASN Number":"34450","Network Name":"WDC-AS Net Gate Telecom S.R.L.","Aliases":"Net Gate Telecom S.R.L.; WDC-AS","Provider Family":"net-gate.ro","RIR Country Code":"RO","Country Name":"Romania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"125","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as WDC-AS (net-gate.ro).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS34985","ASN Number":"34985","Network Name":"NETINNOVATIONLLC-AS-AP - Net Innovation LLC","Aliases":"Net Innovation; netinnovation.net; NETINNOVATIONLLC-AS-AP; net innovation llc","Provider Family":"netinnovation.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting/transit infrastructure","Category":"Current Spamhaus ASN-DROP","Evidence Level":"Strong","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"156","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS34985 is active and in live Spamhaus ASN-DROP under netinnovation.net. Registry and Spamhaus geography/RIR labels differ, so detections should key on ASN rather than geolocation. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NETINNOVATIONLLC-AS-AP (netinnovation.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current active ASN-DROP membership supports blocking while listed.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS35478","ASN Number":"35478","Network Name":"DATACENTER Bunea TELECOM SRL","Aliases":"Bunea TELECOM SRL; DATACENTER","Provider Family":"bunea.eu","RIR Country Code":"RO","Country Name":"Romania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-17","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"233","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DATACENTER (bunea.eu).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS35624","ASN Number":"35624","Network Name":"SILVERSTAR-AS Fast Servers (Pty) Ltd","Aliases":"FineProxy; fineproxy.org; SILVERSTAR-AS; Fast Servers (Pty) Ltd","Provider Family":"fineproxy.org","RIR Country Code":"ZA","Country Name":"South Africa","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Proxy/VPS hosting","Category":"Current Spamhaus ASN-DROP","Evidence Level":"Strong","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"181","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS35624 is active and in live Spamhaus ASN-DROP, mapped to fineproxy.org. The discrepancy between registry holder/country and operator label is material and is preserved rather than silently normalized. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SILVERSTAR-AS (fineproxy.org).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current active ASN-DROP status and proxy use make it a strong account-login control candidate.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS35830","ASN Number":"35830","Network Name":"BTTGROUP-AS Fast Servers (Pty) Ltd","Aliases":"FineProxy; fineproxy.org; BTTGROUP-AS; Fast Servers (Pty) Ltd","Provider Family":"fineproxy.org","RIR Country Code":"ZA","Country Name":"South Africa","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Proxy/VPS hosting","Category":"Current Spamhaus ASN-DROP","Evidence Level":"Strong","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"29","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS35830 is active and in live Spamhaus ASN-DROP, mapped to fineproxy.org. Registry and operator geography differ, so retain both labels. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BTTGROUP-AS (fineproxy.org).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current active ASN-DROP status and proxy use make it a strong account-login control candidate.","Current Community Feed Count":"1","Current Listed IPs":"11","IPsum IPs":"11","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"US:4, AE:3, DE:1, ES:1, FR:1, NL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS36680","ASN Number":"36680","Network Name":"NETIFACELLC - Netiface LLC","Aliases":"Netiface; netiface.co.uk; NETIFACELLC; Netiface LLC","Provider Family":"Netiface","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2026-10-03","Network Type":"Bulletproof / high-risk hosting family","Category":"Source-confirmed BPH (active)","Evidence Level":"High","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"55","Login / Identity Evidence":"No","Actor / Campaign":"bulletproof hosting","Last Evidence":"2026-10-07","Source IDs":"S01, S02, X073, N01, S03","Evidence Summary":"Spamhaus explicitly described Netiface/AS36680 as a bulletproof hoster during an investigation of abuse-resilient infrastructure, and the ASN is in the current ASN-DROP feed. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NETIFACELLC (netiface.co.uk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. High: direct provider-level BPH wording from Spamhaus plus live ASN-DROP membership. Active and announcing routes as Netiface LLC on 2026-09-15; present in current ASN-DROP.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS37707","ASN Number":"37707","Network Name":"SEYCHELLES INTERNET EXCHANGE POINT ASSOCIATION - SEYCHELLES INTERNET EXCHANGE POINT ASSOCIATION","Aliases":"SEY-IX-PEERING; seyix.sc; SEYCHELLES INTERNET EXCHANGE POINT ASSOC; Seychelles Internet Exchange Point Association","Provider Family":"seyix.sc","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"afrinic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"internet exchange / peering ASN","Category":"Current Spamhaus ASN-DROP","Evidence Level":"high","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"234","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows the ASN announced. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SEY-IX-PEERING (seyix.sc).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS38149","ASN Number":"38149","Network Name":"RATELINDONET-AS-ID - PT. Bakrie Telecom","Aliases":"RATELINDONET-AS-ID; bakrietelecom.com; PT. Bakrie Telecom","Provider Family":"bakrietelecom.com","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"telecommunications ISP","Category":"Current Spamhaus ASN-DROP","Evidence Level":"high","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"150","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows the ASN announced. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as RATELINDONET-AS-ID (bakrietelecom.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS38871","ASN Number":"38871","Network Name":"InfoMove-HK-AP - InfoMove Solutions Limited","Aliases":"cloudie.hk; InfoMove-HK-AP","Provider Family":"cloudie.hk","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2009-05-24","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"236","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as InfoMove-HK-AP (cloudie.hk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS38946","ASN Number":"38946","Network Name":"SMARTMEDIANETWORK-1-AS DEMENIN B.V.","Aliases":"SMARTMEDIANETWORK-1-AS; bignet.ua; DEMENIN B.V.","Provider Family":"bignet.ua","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"hosting / transit provider","Category":"Current Spamhaus ASN-DROP","Evidence Level":"high","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"237","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows the ASN announced. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SMARTMEDIANETWORK-1-AS (bignet.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS39600","ASN Number":"39600","Network Name":"BUNNY-TECHNOLOGY-LLC - BUNNY TECHNOLOGY LLC","Aliases":"BUNNY TECHNOLOGY LLC; BUNNY-TECHNOLOGY-LLC","Provider Family":"bunnycommunications.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"65","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BUNNY-TECHNOLOGY-LLC (bunnycommunications.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"9","IPsum IPs":"7","IPsum Score >=3":"2","IPsum Score >=5":"1","Open-Proxy IPs":"1","Data-Shield IPs":"5","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"US:4, SG:2, HK:1, JP:1, TH:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS40193","ASN Number":"40193","Network Name":"AS-TRIT - Trit Networks, LLC","Aliases":"AS-TRIT; trit.net; Trit Networks, LLC","Provider Family":"trit.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"hosting / transit provider","Category":"Current Spamhaus ASN-DROP","Evidence Level":"high","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"164","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows the ASN announced. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AS-TRIT (trit.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS41155","ASN Number":"41155","Network Name":"orbitdc Orbit Telekom Sanayi ve Ticaret Limited Sirketi","Aliases":"orbitdc; OrbitDC; orbittelekom.com; Orbit Telekom Sanayi ve Ticaret Limited; Orbit Telekom Sanayi ve Ticaret Limited Sirketi","Provider Family":"orbittelekom.com","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"data-center / hosting provider","Category":"Current Spamhaus ASN-DROP","Evidence Level":"high","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"80","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows the ASN announced. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as orbitdc (orbittelekom.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS42397","ASN Number":"42397","Network Name":"BUNEA-HIGH-VOLUME-NETWORK Bunea TELECOM SRL","Aliases":"Bunea TELECOM SRL; BUNEA-HIGH-VOLUME-NETWORK","Provider Family":"bunea.eu","RIR Country Code":"RO","Country Name":"Romania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"ISP / network operator","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"185","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BUNEA-HIGH-VOLUME-NETWORK (bunea.eu).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RO:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS42505","ASN Number":"42505","Network Name":"R-TEL-AS \"R-TEL\" LLC","Aliases":"R-TEL-AS; bignet.ua; R-TEL LLC","Provider Family":"bignet.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"telecommunications / hosting network","Category":"Current Spamhaus ASN-DROP","Evidence Level":"high","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"243","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-02","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows the ASN announced. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as R-TEL-AS (bignet.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country. Routing re-verified 2026-10-02: origination resumed after the dormant period recorded in the previous snapshot. RIR object remains active. ASN-DROP membership unchanged, so tier and enablement are unchanged.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS43444","ASN Number":"43444","Network Name":"BNS-AS Fast Servers (Pty) Ltd","Aliases":"BNS-AS; FineProxy; fineproxy.org; Fast Servers (Pty) Ltd","Provider Family":"fineproxy.org","RIR Country Code":"ZA","Country Name":"South Africa","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"proxy / VPS hosting provider","Category":"Current Spamhaus ASN-DROP","Evidence Level":"high","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"53","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows the ASN announced. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BNS-AS (fineproxy.org).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country.","Current Community Feed Count":"1","Current Listed IPs":"9","IPsum IPs":"9","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"NL:3, RU:2, UA:2, ES:1, FR:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS43463","ASN Number":"43463","Network Name":"BST-LT INFOCOM UK LTD","Aliases":"BST-LT; bst.lt; INFOCOM UK LTD","Provider Family":"bst.lt","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"telecommunications / hosting provider","Category":"Current Spamhaus ASN-DROP","Evidence Level":"high","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"141","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows the ASN announced. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BST-LT (bst.lt).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS43481","ASN Number":"43481","Network Name":"PITLINE-AS Pitline Ltd","Aliases":"pitline.net; PITLINE-AS","Provider Family":"pitline.net","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-04-29","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"245","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as PITLINE-AS (pitline.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS43668","ASN Number":"43668","Network Name":"BIGNET-AS \"AS43668\" LLC","Aliases":"BIGNET-AS; bignet.ua","Provider Family":"bignet.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"telecommunications / hosting provider","Category":"Current Spamhaus ASN-DROP","Evidence Level":"high","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"135","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows the ASN announced. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BIGNET-AS (bignet.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS43743","ASN Number":"43743","Network Name":"KRUIZUA-AS Kruiz LLC","Aliases":"KRUIZUA-AS; bignet.ua; Kruiz LLC","Provider Family":"bignet.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"telecommunications / hosting provider","Category":"Current Spamhaus ASN-DROP","Evidence Level":"high","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"247","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows the ASN announced. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as KRUIZUA-AS (bignet.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS44208","ASN Number":"44208","Network Name":"Farahoosh Farahoosh Dena PLC","Aliases":"Farahoosh; farahoosh.ir; Farahoosh Dena PLC","Provider Family":"farahoosh.ir","RIR Country Code":"IR","Country Name":"Iran","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"ISP / data-center and hosting provider","Category":"Current Spamhaus ASN-DROP","Evidence Level":"high","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"54","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows the ASN announced. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Farahoosh (farahoosh.ir).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country.","Current Community Feed Count":"1","Current Listed IPs":"6","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"6","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"IR:6"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS44382","ASN Number":"44382","Network Name":"WhiteLabel Fiba Cloud Operation Company, LLC","Aliases":"Fiba Cloud Operation Company, LLC; WhiteLabel","Provider Family":"fibacloud.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"45","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as WhiteLabel (fibacloud.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"15","IPsum IPs":"12","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"3","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"TR:10, US:5"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS44386","ASN Number":"44386","Network Name":"OZON-AS LLC Internet Solutions","Aliases":"OZON-AS; Ozon; ozon.ru; LLC Internet Solutions","Provider Family":"ozon.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"e-commerce / enterprise network","Category":"Current Spamhaus ASN-DROP","Evidence Level":"high","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"137","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows the ASN announced. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as OZON-AS (ozon.ru).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS44559","ASN Number":"44559","Network Name":"ITHOSTLINE IT HOSTLINE LTD","Aliases":"IT HOSTLINE LTD; ITHOSTLINE","Provider Family":"ithostline.com","RIR Country Code":"CY","Country Name":"Cyprus","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"16","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ITHOSTLINE (ithostline.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"4","IPsum IPs":"4","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RO:2, FI:1, RU:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS46370","ASN Number":"46370","Network Name":"GRANDWEB - Grand Web Solutions, Inc.","Aliases":"Grand Web Solutions, Inc.; GRANDWEB","Provider Family":"grandwebsolutions.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"204","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as GRANDWEB (grandwebsolutions.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS46664","ASN Number":"46664","Network Name":"VDI-NETWORK - VolumeDrive","Aliases":"VDI-NETWORK; volumedrive.com; VolumeDrive","Provider Family":"volumedrive.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"VPS / dedicated-server hosting provider","Category":"Current Spamhaus ASN-DROP","Evidence Level":"high","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"38","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows the ASN announced. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as VDI-NETWORK (volumedrive.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS47890","ASN Number":"47890","Network Name":"UNMANAGED-DEDICATED-SERVERS UNMANAGED LTD","Aliases":"UNMANAGED LTD; UNMANAGED-DEDICATED-SERVERS","Provider Family":"bunea.eu","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"14","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as UNMANAGED-DEDICATED-SERVERS (bunea.eu).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"211","IPsum IPs":"173","IPsum Score >=3":"55","IPsum Score >=5":"19","Open-Proxy IPs":"1","Data-Shield IPs":"149","Talos 2024 IPs":"0","Multi-list IPs":"112","Listed-IP Country Mix":"NL:177, GB:32, RO:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS47893","ASN Number":"47893","Network Name":"R-TEL-AS \"R-TEL\" LLC","Aliases":"R-TEL-AS; bignet.ua; R-TEL LLC","Provider Family":"bignet.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting or leased infrastructure; current ASN-DROP","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High: current Spamhaus ASN-DROP","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"250","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"RIPEstat currently sees AS47893 announced. It is in the current Spamhaus ASN-DROP snapshot under bignet.ua. Treat the source network as high-risk infrastructure, not as evidence of a particular actor or nationality. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as R-TEL-AS (bignet.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Active and present in a high-confidence current ASN-DROP feed. A successful interactive user sign-in from this ASN merits rapid review.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS47926","ASN Number":"47926","Network Name":"LIRUKRAINE DEMENIN B.V.","Aliases":"LIRUKRAINE; bignet.ua; DEMENIN B.V.","Provider Family":"bignet.ua","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting or leased infrastructure; current ASN-DROP","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High: current Spamhaus ASN-DROP","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"251","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"RIPEstat currently sees AS47926 announced. It is in the current Spamhaus ASN-DROP snapshot under bignet.ua. The Netherlands registration is administrative context only and does not identify threat-actor nationality. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as LIRUKRAINE (bignet.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Active and present in a high-confidence current ASN-DROP feed.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS47945","ASN Number":"47945","Network Name":"R-TEL-AS \"R-TEL\" LLC","Aliases":"R-TEL-AS; bignet.ua; R-TEL LLC","Provider Family":"bignet.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting or leased infrastructure; current ASN-DROP","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High: current Spamhaus ASN-DROP","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"252","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-02","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"RIPEstat currently sees AS47945 announced. It is in the current Spamhaus ASN-DROP snapshot under bignet.ua. Network registration country must not be used as actor attribution. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as R-TEL-AS (bignet.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Active and present in a high-confidence current ASN-DROP feed. Routing re-verified 2026-10-02: origination resumed after the dormant period recorded in the previous snapshot. RIR object remains active. ASN-DROP membership unchanged, so tier and enablement are unchanged.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS48090","ASN Number":"48090","Network Name":"DMZHOST TECHOFF SRV LIMITED","Aliases":"DMZHOST; dmzhost.co; TECHOFF SRV LIMITED","Provider Family":"dmzhost.co","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Offshore VPS and dedicated hosting; current ASN-DROP","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High: ASN-DROP plus published threat-concentration analysis","FP Risk":"Low-Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"92","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, X045, N01, S03","Evidence Summary":"AS48090 is active and appears in the current Spamhaus ASN-DROP. Team Cymru also profiled DMZHOST while tracing Metasploit C2 and described it among hosting providers with a disproportionately high concentration of malicious activity. This supports high-risk network treatment without assigning actor nationality. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DMZHOST (dmzhost.co).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Two independent high-quality sources support risk, and the ASN is currently announced.","Current Community Feed Count":"2","Current Listed IPs":"184","IPsum IPs":"146","IPsum Score >=3":"79","IPsum Score >=5":"34","Open-Proxy IPs":"0","Data-Shield IPs":"164","Talos 2024 IPs":"0","Multi-list IPs":"126","Listed-IP Country Mix":"AD:184"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS48198","ASN Number":"48198","Network Name":"AVTOTRANS-EURO-AS AVTOTRANS-EURO LLC","Aliases":"AVTOTRANS-EURO-AS; avtotrans; AVTOTRANS-EURO LLC","Provider Family":"avtotrans","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Small network operator; current ASN-DROP","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High: current Spamhaus ASN-DROP","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"177","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"RIPEstat currently sees AS48198 announced, and the ASN is in the current Spamhaus ASN-DROP snapshot. The holder name alone does not establish the service model or complicity. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AVTOTRANS-EURO-AS (avtotrans).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current high-confidence feed inclusion outweighs uncertainty in the business label.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS48214","ASN Number":"48214","Network Name":"GAJNET-CDN-IRAN Atis Omran Sevin PSJ","Aliases":"lordvps.net; GAJNET-CDN-IRAN","Provider Family":"lordvps.net","RIR Country Code":"IR","Country Name":"Iran","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-09-07","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"253","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as GAJNET-CDN-IRAN (lordvps.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS48589","ASN Number":"48589","Network Name":"TIGER Tiger Network Limited","Aliases":"TIGER; imtigernet; Tiger Network Limited","Provider Family":"imtigernet","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting or network services; current ASN-DROP","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High: current Spamhaus ASN-DROP","FP Risk":"Low-Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"165","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"RIPEstat currently sees AS48589 announced. It is in the current Spamhaus ASN-DROP snapshot. The ASN should be treated as a high-risk source signal, while an individual event still requires identity and device context. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as TIGER (imtigernet).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Active and present in a high-confidence current ASN-DROP feed.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS48693","ASN Number":"48693","Network Name":"NTSERVICE-AS Rices Privately owned enterprise","Aliases":"NTSERVICE-AS; ntup.net; Rices Privately owned enterprise","Provider Family":"ntup.net","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting or network services; current ASN-DROP","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High: current Spamhaus ASN-DROP","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"81","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"RIPEstat currently sees AS48693 announced, and it appears in the current Spamhaus ASN-DROP snapshot. Registry country is context only and is not actor attribution. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NTSERVICE-AS (ntup.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Active and present in a high-confidence current ASN-DROP feed.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"UA:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS49418","ASN Number":"49418","Network Name":"AS-NETSHIELD NETSHIELD LTD","Aliases":"AS-NETSHIELD; chosting.solutions; NETSHIELD LTD","Provider Family":"chosting.solutions","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting or network services; current ASN-DROP","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High: current Spamhaus ASN-DROP","FP Risk":"Low-Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"77","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"RIPEstat currently sees AS49418 announced, and the ASN is in the current Spamhaus ASN-DROP snapshot under chosting.solutions. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AS-NETSHIELD (chosting.solutions).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Active and present in a high-confidence current ASN-DROP feed.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS49581","ASN Number":"49581","Network Name":"TUBE-HOSTING Ferdinand Zink trading as Tube-Hosting","Aliases":"Ferdinand Zink trading as Tube-Hosting; TUBE-HOSTING","Provider Family":"tube-hosting.de","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"17","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as TUBE-HOSTING (tube-hosting.de).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"8","IPsum IPs":"4","IPsum Score >=3":"1","IPsum Score >=5":"1","Open-Proxy IPs":"0","Data-Shield IPs":"6","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"NL:7, UA:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS51124","ASN Number":"51124","Network Name":"ITPLUS-UA-AS FOP Dolgiy Andriy Fedorovuch","Aliases":"ITPLUS-UA-AS; bignet.ua; FOP Dolgiy Andriy Fedorovuch","Provider Family":"bignet.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting or leased infrastructure; current ASN-DROP","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High: current Spamhaus ASN-DROP","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"257","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"RIPEstat currently sees AS51124 announced. It is in the current Spamhaus ASN-DROP snapshot under bignet.ua. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ITPLUS-UA-AS (bignet.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Active and present in a high-confidence current ASN-DROP feed.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS51396","ASN Number":"51396","Network Name":"PFCLOUD Pfcloud UG (haftungsbeschrankt)","Aliases":"PFCLOUD; pfcloud.io; Pfcloud UG (haftungsbeschrankt); Pfcloud UG","Provider Family":"PFCLOUD","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Bulletproof / high-risk hosting family","Category":"BPH facilitator / upstream risk (active)","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"41","Login / Identity Evidence":"No","Actor / Campaign":"upstream/facilitation for proliferating BPH networks","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, X053, X054, X076, N01, S03","Evidence Summary":"Spamhaus described Pfcloud and aurologic as known in anti-abuse circles for persistent proliferation of bulletproof hosts. AS51396 is also present in the live ASN-DROP feed; this row labels facilitation/uplink risk rather than asserting Pfcloud owns every downstream BPH. AS51396 is active and in current Spamhaus ASN-DROP. Pfcloud publicly offers KVM VPS, dedicated servers, reseller hosting, and BGP services; URLhaus maintains an ASN page for malware-distribution URLs hosted there. Inclusion does not imply every tenant is malicious. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as PFCLOUD (pfcloud.io).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current high-confidence adverse designation, active routing, and direct VPS service model. High for current feed status and facilitation role; deliberately narrower than provider-level criminal attribution. Active and announcing routes as Pfcloud UG on 2026-09-15; present in current ASN-DROP.","Current Community Feed Count":"3","Current Listed IPs":"552","IPsum IPs":"549","IPsum Score >=3":"24","IPsum Score >=5":"1","Open-Proxy IPs":"3","Data-Shield IPs":"165","Talos 2024 IPs":"0","Multi-list IPs":"164","Listed-IP Country Mix":"DE:341, NL:211"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS51447","ASN Number":"51447","Network Name":"ROOTLAYERNET RootLayer Web Services LLC","Aliases":"ROOTLAYERNET; rootlayer.net; RootLayer Web Services LLC","Provider Family":"rootlayer.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"VPS or dedicated hosting; current ASN-DROP","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High: current Spamhaus ASN-DROP","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"86","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, X055, N01, S03","Evidence Summary":"RIPEstat currently sees AS51447 announced. It is in current Spamhaus ASN-DROP, and RootLayer publicly markets server hosting. The designation is an infrastructure risk signal, not a claim that every customer is malicious. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ROOTLAYERNET (rootlayer.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Active current ASN-DROP network with a server-hosting service model.","Current Community Feed Count":"1","Current Listed IPs":"6","IPsum IPs":"6","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"NL:6"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS51511","ASN Number":"51511","Network Name":"TRADE-EXPRESS-AS LLC \"Teleradio Company Traide-Express\"","Aliases":"LLC Teleradio Company Traide-Express; TRADE-EXPRESS-AS","Provider Family":"pitline.net","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"138","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as TRADE-EXPRESS-AS (pitline.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS51722","ASN Number":"51722","Network Name":"AS-PIXOOF PIXOOF TEKNOLOJI ANONIM SIRKETI","Aliases":"PIXOOF TEKNOLOJI ANONIM SIRKETI; AS-PIXOOF","Provider Family":"pixoof.com","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"26","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AS-PIXOOF (pixoof.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS52209","ASN Number":"52209","Network Name":"LORDVPSNLNETWORKNL Atis Omran Sevin PSJ","Aliases":"Atis Omran Sevin PSJ; LORDVPSNLNETWORKNL","Provider Family":"lordvps.net","RIR Country Code":"IR","Country Name":"Iran","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"19","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as LORDVPSNLNETWORKNL (lordvps.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS53958","ASN Number":"53958","Network Name":"BART-BM - AUPROXIES LLC","Aliases":"BART-BM; auproxies.com; AUPROXIES LLC","Provider Family":"auproxies.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Proxy infrastructure; current ASN-DROP","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High: current Spamhaus ASN-DROP","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"114","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"RIPEstat currently sees AS53958 announced. It is in current Spamhaus ASN-DROP and the registered organization/domain explicitly identifies proxy infrastructure. Proxy exits can conceal the true user origin, so geography is not actor attribution. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BART-BM (auproxies.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Active high-confidence adverse ASN and a proxy service model are directly relevant to identity-origin monitoring.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS54497","ASN Number":"54497","Network Name":"LHWEBTECH-AS - American Domain Names LLC","Aliases":"lhwebtech.com; LHWEBTECH-AS","Provider Family":"lhwebtech.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2026-02-02","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"259","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as LHWEBTECH-AS (lhwebtech.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS54801","ASN Number":"54801","Network Name":"ZILLION-NETWORK - Zillion Network Inc.","Aliases":"Zillion Network Inc.; ZILLION-NETWORK","Provider Family":"zillionnetwork.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"ISP / network operator","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"102","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ZILLION-NETWORK (zillionnetwork.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"20","IPsum IPs":"12","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"5","Data-Shield IPs":"7","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"HK:8, US:5, SG:4, CA:1, JP:1, PH:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS55154","ASN Number":"55154","Network Name":"MADGEN-01 - Madgenius.com","Aliases":"Madgenius.com; MADGEN-01","Provider Family":"madgenius.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2026-08-13","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"260","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as MADGEN-01 (madgenius.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS55933","ASN Number":"55933","Network Name":"CLOUDIE-AS-AP - Cloudie Limited","Aliases":"Cloudie Limited; CLOUDIE-AS-AP","Provider Family":"cloudie.hk","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"27","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CLOUDIE-AS-AP (cloudie.hk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"51","IPsum IPs":"35","IPsum Score >=3":"6","IPsum Score >=5":"5","Open-Proxy IPs":"8","Data-Shield IPs":"22","Talos 2024 IPs":"0","Multi-list IPs":"14","Listed-IP Country Mix":"HK:45, CN:3, US:2, JP:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS56362","ASN Number":"56362","Network Name":"PITLINE-AS TMN SA","Aliases":"pitline.net; PITLINE-AS","Provider Family":"pitline.net","RIR Country Code":"CH","Country Name":"Switzerland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-04-29","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"263","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as PITLINE-AS (pitline.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS56584","ASN Number":"56584","Network Name":"INTER-IX InterEdge B.V.","Aliases":"serverion.com; INTER-IX","Provider Family":"serverion.com","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2017-09-04","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"264","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as INTER-IX (serverion.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS57100","ASN Number":"57100","Network Name":"WEBNETWORK Individual entrepreneur Dyachenko Valentina Ivanovna","Aliases":"Individual entrepreneur Dyachenko Valent; WEBNETWORK","Provider Family":"pitline.net","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"ISP / network operator","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"147","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as WEBNETWORK (pitline.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS57415","ASN Number":"57415","Network Name":"R-TEL-AS \"R-TEL\" LLC","Aliases":"R-TEL-AS; bignet.ua; R-TEL LLC","Provider Family":"bignet.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting or leased infrastructure; current ASN-DROP","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High: current Spamhaus ASN-DROP","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"266","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"RIPEstat currently sees AS57415 announced. It is in the current Spamhaus ASN-DROP snapshot under bignet.ua. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as R-TEL-AS (bignet.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Active and present in a high-confidence current ASN-DROP feed.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS57509","ASN Number":"57509","Network Name":"LL-Investment-Ltd L&L Investment Ltd.","Aliases":"LL-Investment-Ltd; cloudbs.biz; L&L Investment Ltd.","Provider Family":"cloudbs.biz","RIR Country Code":"BG","Country Name":"Bulgaria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Cloud or hosting services; current ASN-DROP","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High: current Spamhaus ASN-DROP","FP Risk":"Low-Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"133","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"RIPEstat currently sees AS57509 announced. It is in the current Spamhaus ASN-DROP snapshot under cloudbs.biz. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as LL-Investment-Ltd (cloudbs.biz).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Active and present in a high-confidence current ASN-DROP feed.","Current Community Feed Count":"2","Current Listed IPs":"6","IPsum IPs":"5","IPsum Score >=3":"3","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"5","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"BG:6"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS58192","ASN Number":"58192","Network Name":"DDOS-PROTECTION-GAJNET Atis Omran Sevin PSJ","Aliases":"Atis Omran Sevin PSJ; DDOS-PROTECTION-GAJNET","Provider Family":"lordvps.net","RIR Country Code":"IR","Country Name":"Iran","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"268","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DDOS-PROTECTION-GAJNET (lordvps.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS58854","ASN Number":"58854","Network Name":"kaopy - Kaopu Cloud","Aliases":"Kaopu Cloud; kaopy","Provider Family":"kaopuyun.com","RIR Country Code":"CN","Country Name":"China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"151","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as kaopy (kaopuyun.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"3","IPsum IPs":"3","IPsum Score >=3":"1","IPsum Score >=5":"1","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"CN:3"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS58961","ASN Number":"58961","Network Name":"OPENIP-AS - Perhimpunan Klik Indonesia","Aliases":"klikindonesia.or.id; OPENIP-AS","Provider Family":"klikindonesia.or.id","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-16","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"269","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as OPENIP-AS (klikindonesia.or.id).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS59425","ASN Number":"59425","Network Name":"HORIZONMSK-AS Chang Way Technologies Co. Limited","Aliases":"changway.hk; HORIZONMSK-AS","Provider Family":"changway.hk","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-02-01","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"270","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as HORIZONMSK-AS (changway.hk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS59651","ASN Number":"59651","Network Name":"AS-QualityNetwork Alex Largman","Aliases":"Alex Largman; AS-QualityNetwork","Provider Family":"fineproxy.org","RIR Country Code":"IL","Country Name":"Israel","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"28","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AS-QualityNetwork (fineproxy.org).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"23","IPsum IPs":"23","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"NL:8, US:6, DE:3, FR:3, RU:2, GB:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS59683","ASN Number":"59683","Network Name":"iridatelecom VipNet Ltd","Aliases":"vip-net.net; iridatelecom","Provider Family":"vip-net.net","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2018-03-27","Network Type":"ISP / network operator","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"271","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as iridatelecom (vip-net.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS60842","ASN Number":"60842","Network Name":"HUIZE-HOLDINGS-AS Huize Holdings LLC","Aliases":"62yun.com; HUIZE-HOLDINGS-AS","Provider Family":"62yun.com","RIR Country Code":"KG","Country Name":"Kyrgyzstan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-11-07","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"272","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as HUIZE-HOLDINGS-AS (62yun.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS61432","ASN Number":"61432","Network Name":"VAIZ-AS TOV VAIZ PARTNER","Aliases":"link-host.com; VAIZ-AS","Provider Family":"link-host.com","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-07-02","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"273","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as VAIZ-AS (link-host.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS61879","ASN Number":"61879","Network Name":"AS61879 - America Latina Educacional Adm. e Servicos LTDA","Aliases":"América Latina Educacional Adm. e Serviç; América_Latina_Educacional_Adm._e_Serviços_LTDA","Provider Family":"aleducacional.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-11-25","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"274","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as América_Latina_Educacional_Adm._e_Serviços_LTDA (aleducacional.com.br).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS62206","ASN Number":"62206","Network Name":"PITLINE-AS Pitline Ltd","Aliases":"Pitline Ltd; PITLINE-AS","Provider Family":"pitline.net","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"69","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as PITLINE-AS (pitline.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"5","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"5","Talos 2024 IPs":"0","Multi-list IPs":"3","Listed-IP Country Mix":"UA:5"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS62240","ASN Number":"62240","Network Name":"Clouvider Clouvider Limited","Aliases":"","Provider Family":"Clouvider","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"United Kingdom","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / colocation / proxy-exit ecosystem","Category":"Local incident plus repeated published identity and intrusion infrastructure","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for successful interactive employee sign-ins. Correlate new device, MFA or passkey changes, token behavior, VPN access, session anomalies, and post-authentication activity before containment.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Local 2026 compromise; Proofpoint cloud credential attacks; Tycoon 2FA; human-operated phishing; Akira and Fog ransomware; TAG-53; ToolShell","Last Evidence":"2026-09-15","Source IDs":"S04, S06, N01, N06, N07, N08, N09, N10, N11, N12, N13, N14, N16, N34","Evidence Summary":"Clouvider AS62240 is legitimate global hosting, transit, and proxy-exit infrastructure repeatedly used for credential replay, phishing authentication, malicious VPN access, ransomware access, and C2. The requester also reported a local 2026 compromise. This supports high-priority monitoring, not a claim of provider complicity.","Analyst Notes":"","Current Community Feed Count":"3","Current Listed IPs":"357","IPsum IPs":"246","IPsum Score >=3":"2","IPsum Score >=5":"1","Open-Proxy IPs":"7","Data-Shield IPs":"140","Talos 2024 IPs":"16","Multi-list IPs":"52","Listed-IP Country Mix":"US:181, GB:77, DE:48, NL:35, BA:3, ME:3, AM:2, IM:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS62380","ASN Number":"62380","Network Name":"BUNEA-HIGH-PEER-NETWORK Bunea TELECOM SRL","Aliases":"bunea.eu; BUNEA-HIGH-PEER-NETWORK","Provider Family":"bunea.eu","RIR Country Code":"RO","Country Name":"Romania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2021-07-01","Network Type":"ISP / network operator","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"275","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BUNEA-HIGH-PEER-NETWORK (bunea.eu).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS62864","ASN Number":"62864","Network Name":"NILAS - net innovation llc","Aliases":"net innovation llc; NILAS","Provider Family":"netinnovation.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"276","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NILAS (netinnovation.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS63881","ASN Number":"63881","Network Name":"MDI-AS-ID - PT. Medianet Digital Indonesia","Aliases":"medianetdigital.co; MDI-AS-ID","Provider Family":"medianetdigital.co","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-04-07","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"277","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as MDI-AS-ID (medianetdigital.co).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS131388","ASN Number":"131388","Network Name":"HTS-AS-VN - VIET NAM HT GROUP JOINT STOCK COMPANY","Aliases":"hts.vn; HTS-AS-VN","Provider Family":"hts.vn","RIR Country Code":"VN","Country Name":"Vietnam","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-08","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"278","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as HTS-AS-VN (hts.vn).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS131750","ASN Number":"131750","Network Name":"SUFIANET-AS-ID - PT Gisindo Inti Solusi","Aliases":"sufia.tv; SUFIANET-AS-ID","Provider Family":"sufia.tv","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-04-07","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"279","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SUFIANET-AS-ID (sufia.tv).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS131831","ASN Number":"131831","Network Name":"NEXONKOREA-AS-KR-KR - NEXON KOREA","Aliases":"NEXON KOREA; MNT-KRNIC-AP","Provider Family":"nexon.co.kr","RIR Country Code":"KR","Country Name":"South Korea","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-02","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"280","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as MNT-KRNIC-AP (nexon.co.kr).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS132574","ASN Number":"132574","Network Name":"AI-1720-132574 - Alpha InfoLab Inc","Aliases":"alphainfolab.com; AI-1720-132574","Provider Family":"alphainfolab.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2022-06-09","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"281","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AI-1720-132574 (alphainfolab.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS132827","ASN Number":"132827","Network Name":"GATEWAY-AS-AP - GATEWAY INC","Aliases":"GATEWAY INC; GATEWAY-AS-AP","Provider Family":"g-w.bz","RIR Country Code":"JP","Country Name":"Japan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"42","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as GATEWAY-AS-AP (g-w.bz).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS132930","ASN Number":"132930","Network Name":"HERBALVE-AS-IN - HERBALVEDA WELLNESS","Aliases":"herbalvedawellness.com; HERBALVE-AS-IN","Provider Family":"herbalvedawellness.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-10-30","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"282","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as HERBALVE-AS-IN (herbalvedawellness.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS133320","ASN Number":"133320","Network Name":"ALPHA-AS-AP - Alpha InfoLab Private limited","Aliases":"Alpha InfoLab Private Limited; ALPHA-AS-AP","Provider Family":"alphainfolab.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"83","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ALPHA-AS-AP (alphainfolab.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS133488","ASN Number":"133488","Network Name":"SERVICE-AS-AP - service limited","Aliases":"servicehk.net; SERVICE-AS-AP","Provider Family":"servicehk.net","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-04-06","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"283","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SERVICE-AS-AP (servicehk.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS133668","ASN Number":"133668","Network Name":"INFOBB-AS-IN - Infolink Broadband Services Pvt Ltd","Aliases":"eikontech.net; INFOBB-AS-IN","Provider Family":"eikontech.net","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-02-22","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"284","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as INFOBB-AS-IN (eikontech.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS133692","ASN Number":"133692","Network Name":"Fastnet-AS-IN - Fastnet Communication Pvt. Ltd.","Aliases":"Fastnet Communication Pvt. Ltd.; Fastnet-AS-IN","Provider Family":"fastnetcpl.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"152","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Fastnet-AS-IN (fastnetcpl.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"IN:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS133731","ASN Number":"133731","Network Name":"CLOUDIE-AS-AP - Cloudie Limited","Aliases":"Cloudie Limited; CLOUDIE-AS-AP","Provider Family":"cloudie.hk","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"63","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CLOUDIE-AS-AP (cloudie.hk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"3","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"HK:3"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS133994","ASN Number":"133994","Network Name":"RMHOSPITALITY-AS-IN - RM HOSPITALITY","Aliases":"rmhospitality.co.in; RMHOSPITALITY-AS-IN","Provider Family":"rmhospitality.co.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-10-30","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"285","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as RMHOSPITALITY-AS-IN (rmhospitality.co.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS134121","ASN Number":"134121","Network Name":"RAINBOW-HK - Rainbow network limited","Aliases":"itsidc.com; RAINBOW-HK","Provider Family":"itsidc.com","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2024-01-09","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"286","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as RAINBOW-HK (itsidc.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS134176","ASN Number":"134176","Network Name":"CLOUDIE-AS-AP - Cloudie Limited","Aliases":"Cloudie Limited; CLOUDIE-AS-AP","Provider Family":"cloudie.hk","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"64","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CLOUDIE-AS-AP (cloudie.hk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"4","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"4","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"US:3, HK:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS134196","ASN Number":"134196","Network Name":"ANYUN-INTERNET-TECHNOLOGY-HK-CO-LIMITED - ANYUN INTERNET TECHNOLOGY (HK) CO.,LIMITED","Aliases":"ANYUN INTERNET TECHNOLOGY (HK) CO.,LIMIT; ANYUN-INTERNET-TECHNOLOGY-HK-CO-LIMITED","Provider Family":"cloudie.hk","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"66","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ANYUN-INTERNET-TECHNOLOGY-HK-CO-LIMITED (cloudie.hk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"3","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"2","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"HK:2, CN:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS135271","ASN Number":"135271","Network Name":"GLOBTELGROUP-AS-AP - Global Telecom Group LLC","Aliases":"globtelgroup.com; GLOBTELGROUP-AS-AP","Provider Family":"globtelgroup.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2017-05-18","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"287","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as GLOBTELGROUP-AS-AP (globtelgroup.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS135388","ASN Number":"135388","Network Name":"RPL-HK - RMP Protection Limited","Aliases":"RMP Protection Limited; RPL-HK","Provider Family":"serveroffer.lt","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"145","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as RPL-HK (serveroffer.lt).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"4","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"4","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"DE:4"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS135752","ASN Number":"135752","Network Name":"EVOKEDS-AS - Evoke Digital Solutions","Aliases":"Evoke Digital Solutions; EVOKEDS-AS","Provider Family":"evokedigital.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"154","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as EVOKEDS-AS (evokedigital.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"IN:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS136367","ASN Number":"136367","Network Name":"HERBZOOT-AS-IN - HERBZOOT HEALTHCARE PVT LTD","Aliases":"herbzoothealthcare.co.in; HERBZOOT-AS-IN","Provider Family":"herbzoothealthcare.co.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-10-30","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"288","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as HERBZOOT-AS-IN (herbzoothealthcare.co.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS136923","ASN Number":"136923","Network Name":"WIT-AS-AP - WitLayer Technologies Inc","Aliases":"thestack.net; WIT-AS-AP","Provider Family":"thestack.net","RIR Country Code":"CN","Country Name":"China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-06-13","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"289","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as WIT-AS-AP (thestack.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS137156","ASN Number":"137156","Network Name":"BLUEB-AS - Blueberry Web - Solutions Pvt Ltd","Aliases":"Blueberry Web - Solutions Pvt Ltd; BLUEB-AS","Provider Family":"blueberrywebs.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"155","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BLUEB-AS (blueberrywebs.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS138687","ASN Number":"138687","Network Name":"XDEER-AS-AP - Xdeer Limited","Aliases":"xdeer.com; XDEER-AS-AP","Provider Family":"xdeer.com","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-06-14","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"290","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as XDEER-AS-AP (xdeer.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS138749","ASN Number":"138749","Network Name":"ROBUSTED-AS-IN - Robustedge Software And Digital Networks Pvt. Ltd.","Aliases":"robustedge.com; ROBUSTED-AS-IN","Provider Family":"robustedge.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-02-10","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"291","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ROBUSTED-AS-IN (robustedge.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS138808","ASN Number":"138808","Network Name":"INTECHMANDIRI-AS-ID - PT. Intech Esa Mandiri","Aliases":"intechmandiri.com; INTECHMANDIRI-AS-ID","Provider Family":"intechmandiri.com","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-12-24","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"292","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as INTECHMANDIRI-AS-ID (intechmandiri.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS138915","ASN Number":"138915","Network Name":"KAOPU-HK - Kaopu Cloud HK Limited","Aliases":"KAOPU-HK; Kaopu Cloud; Kaopu Cloud HK Limited","Provider Family":"KAOPU-HK","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Bulletproof / high-risk hosting family","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"32","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"AS138915 is present in the 2026-09-15 Spamhaus ASN-DROP feed. This review did not find a sufficiently authoritative public source tying the entire ASN to Funnull or another named campaign, so no such alias or actor attribution is asserted. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as KAOPU-HK (kaopuyun.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. High for current Spamhaus feed membership; unproven as a named BPH-provider attribution in the reviewed public reporting. Active and announcing routes as Kaopu Cloud HK Limited on 2026-09-15. Use the live ASN-DROP feed rather than copying this ASN permanently.","Current Community Feed Count":"3","Current Listed IPs":"9","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"8","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"HK:2, RU:2, SG:2, BH:1, JP:1, NP:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS138968","ASN Number":"138968","Network Name":"RAINBOWIDC-AS-AP - rainbow network limited","Aliases":"rainbow network limited; RAINBOWIDC-AS-AP","Provider Family":"itsidc.com","RIR Country Code":"JP","Country Name":"Japan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"126","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as RAINBOWIDC-AS-AP (itsidc.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"2","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"JP:1, TW:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS140125","ASN Number":"140125","Network Name":"CYBERAUTICS-AS-IN - Cyberautics Softwares","Aliases":"cyberauticssoftwares.co.in; CYBERAUTICS-AS-IN","Provider Family":"cyberauticssoftwares.co.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-10-30","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"293","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CYBERAUTICS-AS-IN (cyberauticssoftwares.co.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS140129","ASN Number":"140129","Network Name":"MSBSPL-AS-IN - Maba Safenet Broadband Services Private Limited","Aliases":"Maba Safenet Broadband Services Private; MSBSPL-AS-IN","Provider Family":"mabasafenet.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-05-26","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"294","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as MSBSPL-AS-IN (mabasafenet.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS140155","ASN Number":"140155","Network Name":"HOSTNET-AS-IN - The Pinnacle Group Inc","Aliases":"The Pinnacle Group Inc; HOSTNET-AS-IN","Provider Family":"thepinnaclegroup.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"157","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as HOSTNET-AS-IN (thepinnaclegroup.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS140184","ASN Number":"140184","Network Name":"SFNSNPL-AS - Sfns Network Private Limited","Aliases":"sfns; SFNSNPL-AS","Provider Family":"sfns","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2020-10-30","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"295","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SFNSNPL-AS (sfns).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS140208","ASN Number":"140208","Network Name":"OBHOST-AS-AP - OBHost","Aliases":"obhost.org; OBHOST-AS-AP","Provider Family":"obhost.org","RIR Country Code":"PK","Country Name":"Pakistan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2024-06-12","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"296","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as OBHOST-AS-AP (obhost.org).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS140787","ASN Number":"140787","Network Name":"LAMA-AS-VN - LAM A ARCHITECTURE CONSTRUCTION COMPANY LIMITED","Aliases":"LAM A ARCHITECTURE CONSTRUCTION COMPANY; LAMA-AS-VN","Provider Family":"vinahost.vn","RIR Country Code":"VN","Country Name":"Vietnam","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"159","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as LAMA-AS-VN (vinahost.vn).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS140869","ASN Number":"140869","Network Name":"TGL-AS-AP - Turing Group Limited","Aliases":"Turing Group Limited; TGL-AS-AP","Provider Family":"turingserver.com","RIR Country Code":"NZ","Country Name":"New Zealand","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"60","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as TGL-AS-AP (turingserver.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"US:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS140941","ASN Number":"140941","Network Name":"FULLTIMEHOSTING-AS-AP - Full Time Hosting","Aliases":"Full Time Hosting; FULLTIMEHOSTING-AS-AP","Provider Family":"fulltimehosting.net","RIR Country Code":"PK","Country Name":"Pakistan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"158","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as FULLTIMEHOSTING-AS-AP (fulltimehosting.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS141333","ASN Number":"141333","Network Name":"ROCKETGP-AS-IN - Rocket Media Group","Aliases":"Rocket Media Group; ROCKETGP-AS-IN","Provider Family":"rocketmediagroups.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"153","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ROCKETGP-AS-IN (rocketmediagroups.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS141567","ASN Number":"141567","Network Name":"INTERSP-AS-IN - Interspire Addon","Aliases":"interspireaddon.co.in; INTERSP-AS-IN","Provider Family":"interspireaddon.co.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-04-26","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"297","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as INTERSP-AS-IN (interspireaddon.co.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS141738","ASN Number":"141738","Network Name":"NOORHOSTCOMBD-AS-AP - noorhost.com.bd","Aliases":"noorhost.com.bd; NOORHOSTCOMBD-AS-AP","Provider Family":"noorhost.com.bd","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"111","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NOORHOSTCOMBD-AS-AP (noorhost.com.bd).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS141803","ASN Number":"141803","Network Name":"INVISION-AS-IN - INVISION CHIP TECHNO SOFT","Aliases":"invisionchiptechnosoft.co.in; INVISION-AS-IN","Provider Family":"invisionchiptechnosoft.co.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-10-30","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"298","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as INVISION-AS-IN (invisionchiptechnosoft.co.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS141835","ASN Number":"141835","Network Name":"IMPACT-AS-IN - IMPACT SOFTWARES","Aliases":"impactsoftwares.co.in; IMPACT-AS-IN","Provider Family":"impactsoftwares.co.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-10-30","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"299","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as IMPACT-AS-IN (impactsoftwares.co.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS141836","ASN Number":"141836","Network Name":"IMAGINE-AS-IN - IMAGINE TECHNO SOFT","Aliases":"imaginetechnosoft.co.in; IMAGINE-AS-IN","Provider Family":"imaginetechnosoft.co.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-10-30","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"300","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as IMAGINE-AS-IN (imaginetechnosoft.co.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS141853","ASN Number":"141853","Network Name":"SRJNH-AS-IN - SRJN HOSPITALITY PRIVATE LIMITED","Aliases":"srjnhospitality.com; SRJNH-AS-IN","Provider Family":"srjnhospitality.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-10-30","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"301","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SRJNH-AS-IN (srjnhospitality.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS141875","ASN Number":"141875","Network Name":"ZEN4-AS-IN - Zen4 Soft Solution","Aliases":"zen4softsolution; ZEN4-AS-IN","Provider Family":"zen4softsolution","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-10-30","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"302","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ZEN4-AS-IN (zen4softsolution).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS142002","ASN Number":"142002","Network Name":"SCLOUDPTELTD-AS - Scloud Pte Ltd","Aliases":"Scloud Pte Ltd; SCLOUDPTELTD-AS","Provider Family":"scloud.sg","RIR Country Code":"SG","Country Name":"Singapore","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"101","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SCLOUDPTELTD-AS (scloud.sg).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"78","IPsum IPs":"46","IPsum Score >=3":"17","IPsum Score >=5":"9","Open-Proxy IPs":"2","Data-Shield IPs":"58","Talos 2024 IPs":"0","Multi-list IPs":"28","Listed-IP Country Mix":"US:34, HK:13, SG:11, JP:7, TW:5, TH:3, VN:2, GB:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS142062","ASN Number":"142062","Network Name":"HQTC-AS-AP - qlhost","Aliases":"qlhost.cc; HQTC-AS-AP","Provider Family":"qlhost.cc","RIR Country Code":"TW","Country Name":"Taiwan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-03-06","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"303","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as HQTC-AS-AP (qlhost.cc).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS142430","ASN Number":"142430","Network Name":"DIGIVPS-AS-AP - DIGI VPS","Aliases":"DIGI VPS; DIGIVPS-AS-AP","Provider Family":"digivps.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"160","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DIGIVPS-AS-AP (digivps.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"6","IPsum IPs":"5","IPsum Score >=3":"3","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"5","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"US:6"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS142519","ASN Number":"142519","Network Name":"SMTPM-AS-IN - Smtpmailers Pvt Ltd","Aliases":"Smtpmailers Pvt Ltd; SMTPM-AS-IN","Provider Family":"smtpmailers.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"161","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SMTPM-AS-IN (smtpmailers.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS142622","ASN Number":"142622","Network Name":"DIL-AS-AP - Dream Information Laboratory","Aliases":"Dream Information Laboratory; DIL-AS-AP","Provider Family":"bunnycommunications.com","RIR Country Code":"JP","Country Name":"Japan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"67","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DIL-AS-AP (bunnycommunications.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS146887","ASN Number":"146887","Network Name":"AS146887-42 - IRINN AS-BLOCK","Aliases":"noobtech.in; MAINT-IN-IRINN","Provider Family":"noobtech.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"304","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as MAINT-IN-IRINN (noobtech.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS147034","ASN Number":"147034","Network Name":"BAREBOXCOMBD-AS-AP - barebox.com.bd","Aliases":"barebox.com.bd; BAREBOXCOMBD-AS-AP","Provider Family":"barebox.com.bd","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"305","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BAREBOXCOMBD-AS-AP (barebox.com.bd).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS147211","ASN Number":"147211","Network Name":"PRAGATHI-AS-IN - PRAGATHI ENTERPRISES","Aliases":"PRAGATHI ENTERPRISES; PRAGATHI-AS-IN","Provider Family":"onlinepragathi.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"306","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as PRAGATHI-AS-IN (onlinepragathi.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS147269","ASN Number":"147269","Network Name":"DATAWINGS-AS-IN - Datawings Teleinfra Pvt Ltd","Aliases":"datawingstel.in; DATAWINGS-AS-IN","Provider Family":"datawingstel.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-02","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"307","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DATAWINGS-AS-IN (datawingstel.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS147287","ASN Number":"147287","Network Name":"DATAPARA1-AS-IN - DATAPARADISE","Aliases":"DATAPARADISE; DATAPARA1-AS-IN","Provider Family":"dataparadise.net","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"162","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DATAPARA1-AS-IN (dataparadise.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS147291","ASN Number":"147291","Network Name":"KHALIDGROUP-AS-AP - KHALID GROUP","Aliases":"khalidgroup.co; KHALIDGROUP-AS-AP","Provider Family":"khalidgroup.co","RIR Country Code":"PK","Country Name":"Pakistan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-05-05","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"308","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as KHALIDGROUP-AS-AP (khalidgroup.co).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS149181","ASN Number":"149181","Network Name":"BHAGWAT-AS-IN - BHAGWAT SOFTWARE","Aliases":"BHAGWAT SOFTWARE; BHAGWAT-AS-IN","Provider Family":"bhagwatsoft.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"309","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BHAGWAT-AS-IN (bhagwatsoft.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS149196","ASN Number":"149196","Network Name":"ZAIFCOMP-AS-IN - Zaif Computers","Aliases":"Zaif Computers; ZAIFCOMP-AS-IN","Provider Family":"zaifcomp.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"310","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ZAIFCOMP-AS-IN (zaifcomp.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS149197","ASN Number":"149197","Network Name":"GIRDHARI-AS-IN - Girdhari Computers","Aliases":"Girdhari Computers; GIRDHARI-AS-IN","Provider Family":"girdharicomp.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"311","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as GIRDHARI-AS-IN (girdharicomp.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS149208","ASN Number":"149208","Network Name":"RAKESSEN-AS-IN - RAKESH TELESOFT","Aliases":"RAKESH TELESOFT; RAKESSEN-AS-IN","Provider Family":"telerakesh.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"312","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as RAKESSEN-AS-IN (telerakesh.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS149242","ASN Number":"149242","Network Name":"ANANYAA-AS-IN - ANANYA COMPUTERS","Aliases":"ANANYA COMPUTERS; ANANYAA-AS-IN","Provider Family":"ananyacomp.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"313","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ANANYAA-AS-IN (ananyacomp.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS149286","ASN Number":"149286","Network Name":"NETINNOVATIONLLC-AS-AP - net innovation llc","Aliases":"netinnovation.net; NETINNOVATIONLLC-AS-AP","Provider Family":"netinnovation.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"314","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NETINNOVATIONLLC-AS-AP (netinnovation.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS149978","ASN Number":"149978","Network Name":"SPNHOST-AS-AP - SPNHOST","Aliases":"SPNHOST; SPNHOST-AS-AP","Provider Family":"spnhost.com.bd","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"315","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SPNHOST-AS-AP (spnhost.com.bd).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS150030","ASN Number":"150030","Network Name":"ALGO-AS-IN - ALGOZINI SERVICES PRIVATE LIMITED","Aliases":"algoz.co.in; ALGO-AS-IN","Provider Family":"algoz.co.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-10-30","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"316","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ALGO-AS-IN (algoz.co.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS150036","ASN Number":"150036","Network Name":"HEEBS-AS-IN - HEEBS HEALTHCARE PRIVATE LIMITED","Aliases":"heebshealthcare.co.in; HEEBS-AS-IN","Provider Family":"heebshealthcare.co.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-10-30","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"317","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as HEEBS-AS-IN (heebshealthcare.co.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS150082","ASN Number":"150082","Network Name":"GARGASSO-AS-IN - Garg Associate","Aliases":"isofttechnology.net; GARGASSO-AS-IN","Provider Family":"isofttechnology.net","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-10-30","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"318","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as GARGASSO-AS-IN (isofttechnology.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS150091","ASN Number":"150091","Network Name":"VEDIMA-AS-IN - VEDIMANTRA LIFECARE PRIVATE LIMITED","Aliases":"vedimantra.co.in; VEDIMA-AS-IN","Provider Family":"vedimantra.co.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-10-30","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"319","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as VEDIMA-AS-IN (vedimantra.co.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS150100","ASN Number":"150100","Network Name":"ARKCOM-AS-IN - A Telecommunications Pvt Ltd.","Aliases":"arkcomtele.com; ARKCOM-AS-IN","Provider Family":"arkcomtele.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-10-30","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"320","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ARKCOM-AS-IN (arkcomtele.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS150101","ASN Number":"150101","Network Name":"YASHITS-AS-IN - Yash It Solutions","Aliases":"ithostline.com; YASHITS-AS-IN","Provider Family":"ithostline.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-10-30","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"321","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as YASHITS-AS-IN (ithostline.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS150102","ASN Number":"150102","Network Name":"ITSERVICE-AS-IN - PRIYANKA SOLUTION AND SERVICES","Aliases":"ithostline.com; ITSERVICE-AS-IN","Provider Family":"ithostline.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-11-02","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"322","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ITSERVICE-AS-IN (ithostline.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS150604","ASN Number":"150604","Network Name":"GLOBALSOL-AS-IN - Global Site Solution","Aliases":"globalsol.co.in; GLOBALSOL-AS-IN","Provider Family":"globalsol.co.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-11-01","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"323","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as GLOBALSOL-AS-IN (globalsol.co.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS150813","ASN Number":"150813","Network Name":"MINHTHOIPC-VN - Thoi MMO Company Limited","Aliases":"thoimmo.com; MINHTHOIPC-VN","Provider Family":"thoimmo.com","RIR Country Code":"VN","Country Name":"Vietnam","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-02-25","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"324","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as MINHTHOIPC-VN (thoimmo.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS150860","ASN Number":"150860","Network Name":"JETCLOUD-VN - JETCLOUD TECHNOLOGY CO., LTD","Aliases":"JETCLOUD TECHNOLOGY CO., LTD; JETCLOUD-VN","Provider Family":"jetcloud.vn","RIR Country Code":"VN","Country Name":"Vietnam","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-10-27","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"325","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as JETCLOUD-VN (jetcloud.vn).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS151604","ASN Number":"151604","Network Name":"WEBWIRESOLUTIONS-AS-AP - WEB WIRE SOLUTIONS","Aliases":"webwiresolutions.com; WEBWIRESOLUTIONS-AS-AP","Provider Family":"webwiresolutions.com","RIR Country Code":"PK","Country Name":"Pakistan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-11-20","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"326","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as WEBWIRESOLUTIONS-AS-AP (webwiresolutions.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS152149","ASN Number":"152149","Network Name":"AHAMEDIT-AS-AP - Ahamed IT","Aliases":"Ahamed IT; AHAMEDIT-AS-AP","Provider Family":"ahamed.com.bd","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"200","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AHAMEDIT-AS-AP (ahamed.com.bd).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS152170","ASN Number":"152170","Network Name":"SAJIBWEBHOST-AS-AP - Sajib Web Host","Aliases":"sajibhost.com.bd; SAJIBWEBHOST-AS-AP","Provider Family":"sajibhost.com.bd","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2024-04-24","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"327","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SAJIBWEBHOST-AS-AP (sajibhost.com.bd).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS152192","ASN Number":"152192","Network Name":"GMTECH-AS-AP - GM Tech","Aliases":"gmtech.com.bd; GMTECH-AS-AP","Provider Family":"gmtech.com.bd","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2024-03-16","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"328","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as GMTECH-AS-AP (gmtech.com.bd).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS152194","ASN Number":"152194","Network Name":"CTGSERVERLIMITED-AS-AP - CTG Server Limited","Aliases":"CTG Server Limited; CTGSERVERLIMITED-AS-AP","Provider Family":"ctgserver.com","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"1","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CTGSERVERLIMITED-AS-AP (ctgserver.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"28","IPsum IPs":"13","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"10","Data-Shield IPs":"7","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"HK:15, JP:7, SG:4, KR:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS152327","ASN Number":"152327","Network Name":"RASUWEBHOST-AS-AP - Rasu Web Host","Aliases":"Rasu Web Host; RASUWEBHOST-AS-AP","Provider Family":"rasuhost.com.bd","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"329","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as RASUWEBHOST-AS-AP (rasuhost.com.bd).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS152485","ASN Number":"152485","Network Name":"HOSTER-AS-IN - Hosterdaddy Private Limited","Aliases":"Hosterdaddy Private Limited; HOSTER-AS-IN","Provider Family":"hosterdaddy.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"173","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as HOSTER-AS-IN (hosterdaddy.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"NL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS152486","ASN Number":"152486","Network Name":"NTSHIELD-AS-IN - Net Shield Infotech","Aliases":"jdmbroadband.com; NTSHIELD-AS-IN","Provider Family":"jdmbroadband.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2024-06-18","Network Type":"ISP / network operator","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"330","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NTSHIELD-AS-IN (jdmbroadband.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS154177","ASN Number":"154177","Network Name":"LIGHT4-AS-AP - LIGHT NODE LIMITED","Aliases":"LIGHT NODE LIMITED; LIGHT4-AS-AP","Provider Family":"kaopuyun.com","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"59","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as LIGHT4-AS-AP (kaopuyun.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"63","IPsum IPs":"29","IPsum Score >=3":"2","IPsum Score >=5":"1","Open-Proxy IPs":"24","Data-Shield IPs":"21","Talos 2024 IPs":"0","Multi-list IPs":"11","Listed-IP Country Mix":"US:7, TH:5, BR:4, FR:4, KR:4, SA:4, AE:3, EG:3"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS154206","ASN Number":"154206","Network Name":"CDN1COM-AS-AP - CDN1.com Limited","Aliases":"CDN1.com Limited; CDN1COM-AS-AP","Provider Family":"cloudie.hk","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"84","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CDN1COM-AS-AP (cloudie.hk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS197170","ASN Number":"197170","Network Name":"TECHTIES-AS TechTies Inc.","Aliases":"TechTies Inc.; TECHTIES-AS","Provider Family":"hostslick.de","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"93","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as TECHTIES-AS (hostslick.de).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"339","IPsum IPs":"187","IPsum Score >=3":"35","IPsum Score >=5":"9","Open-Proxy IPs":"0","Data-Shield IPs":"318","Talos 2024 IPs":"0","Multi-list IPs":"166","Listed-IP Country Mix":"NL:284, DE:55"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS197176","ASN Number":"197176","Network Name":"KylieCDN-AS Chen Yulin","Aliases":"kyliecdn; KylieCDN-AS","Provider Family":"kyliecdn","RIR Country Code":"CN","Country Name":"China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-08","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"331","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as KylieCDN-AS (kyliecdn).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS197450","ASN Number":"197450","Network Name":"SUNUCUN Sunucun Bilgi Iletisim Teknolojileri ve Ticaret Ltd. Sti.","Aliases":"Sunucun Bilgi Iletisim Teknolojileri ve; SUNUCUN","Provider Family":"sunucun.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"33","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SUNUCUN (sunucun.com.tr).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"10","IPsum IPs":"5","IPsum Score >=3":"1","IPsum Score >=5":"1","Open-Proxy IPs":"1","Data-Shield IPs":"8","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"TR:10"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS197555","ASN Number":"197555","Network Name":"SMARTMIETEN SMARTMIETEN TECH PRIVATE LIMITED","Aliases":"SMARTMIETEN TECH PRIVATE LIMITED; SMARTMIETEN","Provider Family":"smartmieten.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"332","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SMARTMIETEN (smartmieten.in).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS197769","ASN Number":"197769","Network Name":"VPSDEDICATED-AS VPS Dedicated LLC","Aliases":"VPS Dedicated LLC; VPSDEDICATED-AS","Provider Family":"vpsdedicated.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"50","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as VPSDEDICATED-AS (vpsdedicated.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"107","IPsum IPs":"89","IPsum Score >=3":"35","IPsum Score >=5":"10","Open-Proxy IPs":"0","Data-Shield IPs":"89","Talos 2024 IPs":"0","Multi-list IPs":"71","Listed-IP Country Mix":"SI:107"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS198071","ASN Number":"198071","Network Name":"BERCHSOLUTIONS-AS Berch Solutions Limited","Aliases":"Berch Solutions Limited; BERCHSOLUTIONS-AS","Provider Family":"berch.co.uk","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"192","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BERCHSOLUTIONS-AS (berch.co.uk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS198189","ASN Number":"198189","Network Name":"STEALTHVM Throttle Limited","Aliases":"Throttle Limited; STEALTHVM","Provider Family":"stealthvm.net","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"203","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as STEALTHVM (stealthvm.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"8","IPsum IPs":"7","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"5","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"SE:8"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS198571","ASN Number":"198571","Network Name":"PlainProxies 3xK Tech GmbH","Aliases":"3xK Tech GmbH; PlainProxies","Provider Family":"plainproxies.com","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"333","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as PlainProxies (plainproxies.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS198926","ASN Number":"198926","Network Name":"Fazed Fazel Rezaei Kalantari","Aliases":"Fazel Rezaei Kalantari; Fazed","Provider Family":"rapidoserver.com","RIR Country Code":"IR","Country Name":"Iran","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"143","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Fazed (rapidoserver.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS198953","ASN Number":"198953","Network Name":"proton66 Proton66 OOO","Aliases":"Proton66 OOO; proton66","Provider Family":"proton66.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"57","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as proton66 (proton66.ru).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"45","IPsum IPs":"45","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"7","Talos 2024 IPs":"0","Multi-list IPs":"7","Listed-IP Country Mix":"RU:45"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS198981","ASN Number":"198981","Network Name":"NETSHIELD-BYOIP NETSHIELD LTD","Aliases":"NETSHIELD LTD; NETSHIELD-BYOIP","Provider Family":"chosting.solutions","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"334","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NETSHIELD-BYOIP (chosting.solutions).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS199420","ASN Number":"199420","Network Name":"FLYGROUP-AS OOO Fly Engeneering Group","Aliases":"OOO Fly Engeneering Group; FLYGROUP-AS","Provider Family":"fly-group.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"117","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as FLYGROUP-AS (fly-group.ru).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"2","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RU:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS199467","ASN Number":"199467","Network Name":"Hossein_Zangooei Hossein Zangooei","Aliases":"swissnetwork.io; Hossein_Zangooei","Provider Family":"swissnetwork.io","RIR Country Code":"IR","Country Name":"Iran","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-10","Network Type":"ISP / network operator","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"335","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Hossein_Zangooei (swissnetwork.io).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS200010","ASN Number":"200010","Network Name":"OLFE Olfe Veri Merkezi Anonim Sirketi","Aliases":"Olfe Veri Merkezi Anonim Sirketi; OLFE","Provider Family":"cantech.international","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"191","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as OLFE (cantech.international).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS200051","ASN Number":"200051","Network Name":"VPSLab-Networks RIZKI ABDUL AZIS","Aliases":"RIZKI ABDUL AZIS; VPSLab-Networks","Provider Family":"kyonix.com","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"9","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as VPSLab-Networks (kyonix.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"4","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"DE:2, NL:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS200130","ASN Number":"200130","Network Name":"SIMON-MARIACHER Simon Mariacher","Aliases":"ryzehosting.com; SIMON-MARIACHER","Provider Family":"ryzehosting.com","RIR Country Code":"AT","Country Name":"Austria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2017-07-07","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"336","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SIMON-MARIACHER (ryzehosting.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS200373","ASN Number":"200373","Network Name":"Drei-K-Tech-GmbH 3xK Tech GmbH","Aliases":"3xK Tech; plainproxies.com; Plain Proxies; Drei-K-Tech-GmbH (infiniteproxies DDoS source); Drei-K-Tech-GmbH; 3xK Tech GmbH","Provider Family":"3xK Tech / Plain Proxies","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Proxy / BYOIP / transit infrastructure","Category":"Current ASN-DROP + recent Microsoft login spraying","Evidence Level":"High","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"68","Login / Identity Evidence":"Yes","Actor / Campaign":"LSHIY password spray","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, X008, N01, S03","Evidence Summary":"Huntress reported roughly 1.5 million Microsoft login attempts per day from about 12,800 rotating IPs in AS200373 during July 2026. AS200373 is in the live Spamhaus ASN-DROP feed. Huntress also observed roughly 1.5 million Microsoft login attempts per day from about 12,800 rotating IPs on this ASN in July 2026, following a malicious BYOIP user's moves between providers. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Drei-K-Tech-GmbH (plainproxies.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current ASN-DROP membership plus recent high-volume credential spraying makes this an immediate identity-control candidate.","Current Community Feed Count":"2","Current Listed IPs":"3163","IPsum IPs":"629","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"2596","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"62","Listed-IP Country Mix":"US:2188, GB:208, BR:184, FR:180, DE:178, CA:95, ES:51, TH:42"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS200499","ASN Number":"200499","Network Name":"EHL-AS Enterprises Holding LTD","Aliases":"Enterprises Holding LTD; EHL-AS","Provider Family":"enterprises-holding","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"337","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as EHL-AS (enterprises-holding).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS200593","ASN Number":"200593","Network Name":"PROSPERO-AS PROSPERO OOO","Aliases":"PROSPERO OOO; PROSPERO-AS","Provider Family":"pro-spero.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"136","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as PROSPERO-AS (pro-spero.ru).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"11","IPsum IPs":"9","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"10","Talos 2024 IPs":"0","Multi-list IPs":"8","Listed-IP Country Mix":"RU:11"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS200671","ASN Number":"200671","Network Name":"START-AS START BUILDING LTD","Aliases":"START BUILDING LTD; START-AS","Provider Family":"start-building","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"338","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as START-AS (start-building).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS200699","ASN Number":"200699","Network Name":"DATASHIELD_NL Datashield, Inc.","Aliases":"Datashield, Inc.; DATASHIELD_NL","Provider Family":"xor.sc","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-12-19","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"339","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DATASHIELD_NL (xor.sc).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS200912","ASN Number":"200912","Network Name":"KRAUSE-AS Joel Krause","Aliases":"Joel Krause; KRAUSE-AS","Provider Family":"hypernex.cc","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"51","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as KRAUSE-AS (hypernex.cc).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"7","IPsum IPs":"4","IPsum Score >=3":"2","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"6","Talos 2024 IPs":"0","Multi-list IPs":"3","Listed-IP Country Mix":"NL:7"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS201249","ASN Number":"201249","Network Name":"IPRO IPRO Sh.p.k.","Aliases":"IPRO Sh.p.k.; IPRO","Provider Family":"iprowireless.com","RIR Country Code":"AL","Country Name":"Albania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"ISP / network operator","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"183","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as IPRO (iprowireless.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"AL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS201292","ASN Number":"201292","Network Name":"AS-AGRO Agrofirma Aleks PP","Aliases":"Agrofirma Aleks PP; AS-AGRO","Provider Family":"agrofirma-aleks","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"340","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AS-AGRO (agrofirma-aleks).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS201380","ASN Number":"201380","Network Name":"ALFABISNES-AS LLC \"Alfa Biznes\"","Aliases":"LLC Alfa Biznes; ALFABISNES-AS","Provider Family":"excitedmatch.com","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"341","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ALFABISNES-AS (excitedmatch.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS201572","ASN Number":"201572","Network Name":"EKO-INICIATIVE-AS ECO-INITIATIVE LLC","Aliases":"ECO-INITIATIVE LLC; EKO-INICIATIVE-AS","Provider Family":"ekoiniciative.pp.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"342","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as EKO-INICIATIVE-AS (ekoiniciative.pp.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS201626","ASN Number":"201626","Network Name":"PODILLIA-AS Podillia-hotel PJSC","Aliases":"Podillia-hotel PJSC; PODILLIA-AS","Provider Family":"bignet.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"343","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as PODILLIA-AS (bignet.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS201738","ASN Number":"201738","Network Name":"UFO-TECHNOLOGIES-LIMITED UFO TECHNOLOGIES LIMITED","Aliases":"Bearhost-linked; changway.hk feed lineage; UFO-TECHNOLOGIES-LIMITED; UFO TECHNOLOGIES LIMITED","Provider Family":"Bearhost-linked","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Bulletproof / high-risk hosting family","Category":"Source-confirmed BPH (active)","Evidence Level":"High","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"78","Login / Identity Evidence":"No","Actor / Campaign":"Bearhost bulletproof-hosting ecosystem","Last Evidence":"2026-09-29","Source IDs":"S01, S02, X072, N01, S03","Evidence Summary":"Spamhaus linked AS201738 to the Bearhost threat actor's BPH comeback and confirmed inclusion in DROP/ASN-DROP. The live feed currently associates the ASN with changway.hk. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as UFO-TECHNOLOGIES-LIMITED (changway.hk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. High: direct BPH/operator linkage by Spamhaus and current block-feed inclusion. Active and announcing routes as UFO TECHNOLOGIES LIMITED on 2026-09-15; present in current ASN-DROP.","Current Community Feed Count":"2","Current Listed IPs":"8","IPsum IPs":"7","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"6","Talos 2024 IPs":"0","Multi-list IPs":"5","Listed-IP Country Mix":"GB:8"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS201813","ASN Number":"201813","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"Contrust Solutions S.R.L.; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"163","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS201824","ASN Number":"201824","Network Name":"stat-cons-as STAT CONSULTING LTD","Aliases":"STAT CONSULTING LTD; stat-cons-as","Provider Family":"stat-cons","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"344","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as stat-cons-as (stat-cons).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS201836","ASN Number":"201836","Network Name":"GARANT-AS Garant-Plus-Inform LLC","Aliases":"Garant-Plus-Inform LLC; GARANT-AS","Provider Family":"garant-plus-inform","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"345","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as GARANT-AS (garant-plus-inform).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS202144","ASN Number":"202144","Network Name":"CHEMPIR-AS TOV CHEMPIR","Aliases":"TOV CHEMPIR; CHEMPIR-AS","Provider Family":"chempir","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"346","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CHEMPIR-AS (chempir).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS202171","ASN Number":"202171","Network Name":"TORERO-AS PP \"TORERO\"","Aliases":"PP TORERO; TORERO-AS","Provider Family":"torero","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"347","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as TORERO-AS (torero).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS202226","ASN Number":"202226","Network Name":"GreatFlower Emil Vitukhnovskii trading as Great Flower","Aliases":"Emil Vitukhnovskii trading as Great Flow; GreatFlower","Provider Family":"flowerproxy.com","RIR Country Code":"IL","Country Name":"Israel","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"5","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as GreatFlower (flowerproxy.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"FI:1, PL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS202267","ASN Number":"202267","Network Name":"DOBROSVIT-AS PP DOBROSVIT-KREDO","Aliases":"PP DOBROSVIT-KREDO; DOBROSVIT-AS","Provider Family":"dobrosvitkredo","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"348","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DOBROSVIT-AS (dobrosvitkredo).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS202302","ASN Number":"202302","Network Name":"NETH-AS NETH LLC","Aliases":"NETH LLC; NETH-AS","Provider Family":"s-host.com.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"349","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NETH-AS (s-host.com.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"5","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"4","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"UA:4, NL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS202306","ASN Number":"202306","Network Name":"HOSTGLOBALPLUS-AS HOSTGLOBAL.PLUS LTD","Aliases":"HostGlobal.plus; Hostry Ltd; HOSTGLOBALPLUS-AS; HOSTGLOBAL.PLUS LTD","Provider Family":"hostglobal.plus","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"VPS/server hosting","Category":"Current Spamhaus ASN-DROP","Evidence Level":"Strong","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"119","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS202306 is in the live Spamhaus ASN-DROP feed, whose policy is limited to cybercrime-controlled, hijacked, or bulletproof-hosted networks after investigation. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as HOSTGLOBALPLUS-AS (hostglobal.plus).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use the continuously refreshed live feed rather than a permanent static label.","Current Community Feed Count":"2","Current Listed IPs":"20","IPsum IPs":"11","IPsum Score >=3":"2","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"20","Talos 2024 IPs":"0","Multi-list IPs":"11","Listed-IP Country Mix":"GB:20"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS202318","ASN Number":"202318","Network Name":"EKOINICIATIVE-AS ECO-INITIATIVE LLC","Aliases":"ECO-INITIATIVE LLC; EKOINICIATIVE-AS","Provider Family":"ekoiniciative.pp.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"350","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as EKOINICIATIVE-AS (ekoiniciative.pp.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS202383","ASN Number":"202383","Network Name":"EL-K-STIL-AS EL.K.STIL LLC","Aliases":"EL.K.STIL LLC; EL-K-STIL-AS","Provider Family":"el-k-stil","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"351","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as EL-K-STIL-AS (el-k-stil).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS202388","ASN Number":"202388","Network Name":"CLUB-NADIYA-AS KP \"CLUB NADIYA\"","Aliases":"KP CLUB NADIYA; CLUB-NADIYA-AS","Provider Family":"club-nadiya","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"352","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CLUB-NADIYA-AS (club-nadiya).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS202412","ASN Number":"202412","Network Name":"OMEGATECH-AS Omegatech LTD","Aliases":"Virtualine; virtualine.org; OMEGATECH-AS; Omegatech LTD","Provider Family":"Virtualine","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Bulletproof / high-risk hosting family","Category":"Source-confirmed BPH (active)","Evidence Level":"High","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"73","Login / Identity Evidence":"No","Actor / Campaign":"bulletproof hosting; botnet command-and-control","Last Evidence":"2026-09-29","Source IDs":"S01, S02, X075, N01, S03","Evidence Summary":"Spamhaus identified Virtualine as a BPH operation and the January-June 2026 Spamhaus botnet report ranked it fifth among newly observed networks with 382 C2 observations and seventeenth among active networks. AS202412 remains in ASN-DROP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as OMEGATECH-AS (virtualine.org).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. High: direct BPH attribution, sustained measured C2 concentration, and current block-feed inclusion. Active and announcing routes as Omegatech LTD on 2026-09-15; present in current ASN-DROP.","Current Community Feed Count":"3","Current Listed IPs":"266","IPsum IPs":"173","IPsum Score >=3":"39","IPsum Score >=5":"3","Open-Proxy IPs":"1","Data-Shield IPs":"231","Talos 2024 IPs":"2","Multi-list IPs":"141","Listed-IP Country Mix":"NL:122, US:87, DE:40, CA:11, TR:6"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS202425","ASN Number":"202425","Network Name":"INT-NETWORK IP Volume inc","Aliases":"IP Volume inc; INT-NETWORK","Provider Family":"ipvolume.net","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"ISP / network operator","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"88","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as INT-NETWORK (ipvolume.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"316","IPsum IPs":"315","IPsum Score >=3":"41","IPsum Score >=5":"10","Open-Proxy IPs":"0","Data-Shield IPs":"75","Talos 2024 IPs":"1","Multi-list IPs":"75","Listed-IP Country Mix":"NL:261, PL:44, DE:9, UA:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS202481","ASN Number":"202481","Network Name":"REAPOLIS-AS LTD \"Reapolis\"","Aliases":"LTD Reapolis; REAPOLIS-AS","Provider Family":"reapolis","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"353","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as REAPOLIS-AS (reapolis).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS203044","ASN Number":"203044","Network Name":"telepatiya Telepatiya Ltd","Aliases":"telepatiya.kz; telepatiya","Provider Family":"telepatiya.kz","RIR Country Code":"KZ","Country Name":"Kazakhstan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-15","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"354","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as telepatiya (telepatiya.kz).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS203120","ASN Number":"203120","Network Name":"GTGL Global Telecom Group LLC","Aliases":"Global Telecom Group LLC; GTGL","Provider Family":"globtelgroup.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"355","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as GTGL (globtelgroup.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS203273","ASN Number":"203273","Network Name":"NetCraftersOU NetCrafters OU","Aliases":"NetCrafters OU; NetCraftersOU","Provider Family":"aeza.net","RIR Country Code":"EE","Country Name":"Estonia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"12","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NetCraftersOU (aeza.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"28","IPsum IPs":"14","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"15","Data-Shield IPs":"5","Talos 2024 IPs":"0","Multi-list IPs":"5","Listed-IP Country Mix":"FI:7, SE:6, US:4, DE:3, NL:3, PL:2, AT:1, FR:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS203861","ASN Number":"203861","Network Name":"MITEFLUX-AS Miteflux Technologies Ltd","Aliases":"Miteflux Technologies Ltd; MITEFLUX-AS","Provider Family":"netiface.co.uk","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"25","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as MITEFLUX-AS (netiface.co.uk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"9","IPsum IPs":"8","IPsum Score >=3":"3","IPsum Score >=5":"1","Open-Proxy IPs":"0","Data-Shield IPs":"7","Talos 2024 IPs":"0","Multi-list IPs":"6","Listed-IP Country Mix":"SE:4, US:4, CH:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS203950","ASN Number":"203950","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-05-31","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"356","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS203999","ASN Number":"203999","Network Name":"GeekyWorks Geekyworks IT Solutions Pvt Ltd","Aliases":"Geekyworks IT Solutions Pvt Ltd; GeekyWorks","Provider Family":"gwhostinglabs.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-03-17","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"357","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as GeekyWorks (gwhostinglabs.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS204428","ASN Number":"204428","Network Name":"SS-Net SS-Net","Aliases":"SS-Net","Provider Family":"ssnet.eu","RIR Country Code":"BG","Country Name":"Bulgaria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"121","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SS-Net (ssnet.eu).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS204490","ASN Number":"204490","Network Name":"ASKONTEL Kontel LLC","Aliases":"Kontel LLC; ASKONTEL","Provider Family":"contell.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"106","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ASKONTEL (contell.ru).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"7","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"2","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"RU:7"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS204502","ASN Number":"204502","Network Name":"LIVELA-AS PE Commercial company Livela","Aliases":"livela; LIVELA-AS","Provider Family":"livela","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2021-09-22","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"358","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as LIVELA-AS (livela).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS204552","ASN Number":"204552","Network Name":"POPILNYANET-AS POPILNYA.NET LLC","Aliases":"POPILNYA.NET LLC; POPILNYANET-AS","Provider Family":"bignet.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"110","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as POPILNYANET-AS (bignet.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"UA:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS204610","ASN Number":"204610","Network Name":"IMASOFTWARE-AS I.M.A. Software Future Solutions Ltd","Aliases":"imasfs.com; IMASOFTWARE-AS","Provider Family":"imasfs.com","RIR Country Code":"CY","Country Name":"Cyprus","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-04-08","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"359","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as IMASOFTWARE-AS (imasfs.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS204794","ASN Number":"204794","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-05-26","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"360","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS204868","ASN Number":"204868","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-16","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"361","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS204872","ASN Number":"204872","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-16","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"362","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS205083","ASN Number":"205083","Network Name":"DATASHIELD_FILTER Datashield, Inc.","Aliases":"xor.sc; DATASHIELD_FILTER","Provider Family":"xor.sc","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2021-06-12","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"363","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DATASHIELD_FILTER (xor.sc).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS205301","ASN Number":"205301","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-16","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"364","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS205397","ASN Number":"205397","Network Name":"AS-69HOST 69HOST LLC","Aliases":"69HOST LLC; AS-69HOST","Provider Family":"69host.cc","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"75","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AS-69HOST (69host.cc).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"3","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"UA:3"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS205486","ASN Number":"205486","Network Name":"LKGF LUAN KLEBER GOMES FARIAS","Aliases":"LUAN KLEBER GOMES FARIAS; LKGF","Provider Family":"sunucun.com.tr","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"365","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as LKGF (sunucun.com.tr).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS205745","ASN Number":"205745","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-07-06","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"366","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS205770","ASN Number":"205770","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"Contrust Solutions S.R.L.; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-11","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"367","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS205884","ASN Number":"205884","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"Contrust Solutions S.R.L.; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"368","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS205997","ASN Number":"205997","Network Name":"Vlad_Cojuhari Vlad Cojuhari","Aliases":"Vlad_Cojuhari","Provider Family":"zerolimit-servers.cool","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-08-25","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"369","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Vlad_Cojuhari (zerolimit-servers.cool).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS206005","ASN Number":"206005","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-05-14","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"370","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS206127","ASN Number":"206127","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-15","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"371","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS206305","ASN Number":"206305","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-19","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"372","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS206340","ASN Number":"206340","Network Name":"AMPERAURA-AS Contrust Solutions S.R.L.","Aliases":"kontrast.md; AMPERAURA-AS","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-28","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"373","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AMPERAURA-AS (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS206378","ASN Number":"206378","Network Name":"STOLITOMSON-AS FOP Dmytro Nedilskyi","Aliases":"STOLITOMSON-AS","Provider Family":"zerolimit-servers.cool","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"189","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as STOLITOMSON-AS (zerolimit-servers.cool).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"10","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"10","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"UA:10"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS206413","ASN Number":"206413","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"Contrust Solutions S.R.L.; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-07-27","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"374","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS206479","ASN Number":"206479","Network Name":"AceRDP AceRDP Ltd","Aliases":"AceRDP Ltd; AceRDP","Provider Family":"acerdp.io","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"23","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AceRDP (acerdp.io).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"DE:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS206535","ASN Number":"206535","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"Contrust Solutions S.R.L.; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-07-27","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"375","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS206560","ASN Number":"206560","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"Contrust Solutions S.R.L.; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-07-28","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"376","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS206582","ASN Number":"206582","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2022-11-28","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"377","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS206590","ASN Number":"206590","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2019-02-08","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"378","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS206623","ASN Number":"206623","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-06-12","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"379","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS206644","ASN Number":"206644","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-06-12","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"380","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS206728","ASN Number":"206728","Network Name":"MEDIALAND-AS Media Land LLC","Aliases":"MediaLand; yalishanda; MEDIALAND-AS; Media Land LLC","Provider Family":"Media Land / ML Cloud","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Bulletproof / high-risk hosting family","Category":"Source-confirmed sanctioned BPH (active)","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"89","Login / Identity Evidence":"No","Actor / Campaign":"LockBit; BlackSuit; Play ransomware; phishing; brute-force attacks; malware delivery","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S11, S20, N01, S03","Evidence Summary":"Team Cymru maps sanctioned Media Land to AS206728 and found the network continuing to announce infrastructure and host suspicious domains after designation. Treasury described Media Land as a BPH provider supporting ransomware and attacks against U.S. critical infrastructure. Government and technical reporting identify Media Land as bulletproof-hosting infrastructure. AS206728 remains in current ASN-DROP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as MEDIALAND-AS (sshvps.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. High: exact ASN mapping, provider-level government designation, and post-designation activity measurement. Active and announcing routes as Media Land LLC on 2026-09-15; present in the current Spamhaus ASN-DROP snapshot.","Current Community Feed Count":"1","Current Listed IPs":"4","IPsum IPs":"4","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RU:4"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS206744","ASN Number":"206744","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2022-10-07","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"381","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS206750","ASN Number":"206750","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-17","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"382","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS207043","ASN Number":"207043","Network Name":"DEDIK-IO DEDIK SERVICES LIMITED","Aliases":"DEDIK SERVICES LIMITED; DEDIK-IO","Provider Family":"dedik.io","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"10","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DEDIK-IO (dedik.io).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"51","IPsum IPs":"22","IPsum Score >=3":"3","IPsum Score >=5":"1","Open-Proxy IPs":"1","Data-Shield IPs":"46","Talos 2024 IPs":"0","Multi-list IPs":"18","Listed-IP Country Mix":"DE:24, US:16, NL:8, FR:2, PL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS207088","ASN Number":"207088","Network Name":"ADOARD ADOARD GLOBAL REACH LLC","Aliases":"ADOARD GLOBAL REACH LLC; ADOARD","Provider Family":"adoard.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"195","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ADOARD (adoard.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS207566","ASN Number":"207566","Network Name":"LD007-AS Chang Way Technologies Co. Limited","Aliases":"changway.hk; LD007-AS","Provider Family":"changway.hk","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-04-18","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"383","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as LD007-AS (changway.hk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS207812","ASN Number":"207812","Network Name":"DM_AUTO DM AUTO EOOD","Aliases":"DM AUTO EOOD; DM_AUTO","Provider Family":"dm-auto.eu","RIR Country Code":"BG","Country Name":"Bulgaria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"120","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DM_AUTO (dm-auto.eu).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"8","IPsum IPs":"8","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"8","Talos 2024 IPs":"0","Multi-list IPs":"8","Listed-IP Country Mix":"SC:8"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS207957","ASN Number":"207957","Network Name":"ServHost-AS SERV.HOST GROUP LTD","Aliases":"SERV.HOST GROUP LTD; ServHost-AS","Provider Family":"serv.host","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"2","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ServHost-AS (serv.host).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"31","IPsum IPs":"11","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"15","Data-Shield IPs":"8","Talos 2024 IPs":"0","Multi-list IPs":"3","Listed-IP Country Mix":"RU:7, NL:6, DE:5, FI:5, PL:2, CZ:1, GB:1, IT:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS207986","ASN Number":"207986","Network Name":"OZON-BANK-AS LLC OZON BANK","Aliases":"LLC OZON BANK; OZON-BANK-AS","Provider Family":"ozon.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"124","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as OZON-BANK-AS (ozon.ru).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS208137","ASN Number":"208137","Network Name":"FPS12 Feo Prest SRL","Aliases":"Feo Prest SRL; FPS12","Provider Family":"feoprest.info","RIR Country Code":"RO","Country Name":"Romania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"108","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as FPS12 (feoprest.info).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"110","IPsum IPs":"88","IPsum Score >=3":"34","IPsum Score >=5":"7","Open-Proxy IPs":"0","Data-Shield IPs":"102","Talos 2024 IPs":"0","Multi-list IPs":"80","Listed-IP Country Mix":"NL:54, DE:52, GB:4"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS208185","ASN Number":"208185","Network Name":"NETGATE-SOLUTION-AS Net Gate Telecom S.R.L.","Aliases":"Net Gate Telecom S.R.L.; NETGATE-SOLUTION-AS","Provider Family":"net-gate.ro","RIR Country Code":"RO","Country Name":"Romania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-09-26","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"384","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NETGATE-SOLUTION-AS (net-gate.ro).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS208198","ASN Number":"208198","Network Name":"Eylul-NET Nese Mala","Aliases":"Nese Mala trading as Moon Dc; Eylul-NET","Provider Family":"eksenbilisim.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"71","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Eylul-NET (eksenbilisim.com.tr).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS208241","ASN Number":"208241","Network Name":"RADIO-LINK-PLUS \"RADIO-LINK PLUS\" LLC","Aliases":"RADIO-LINK PLUS LLC; RADIO-LINK-PLUS","Provider Family":"pitline.net","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"139","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as RADIO-LINK-PLUS (pitline.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"6","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"6","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"UA:6"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS208317","ASN Number":"208317","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"Contrust Solutions S.R.L.; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-24","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"385","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS208525","ASN Number":"208525","Network Name":"AIRULIMITED Airu Limited","Aliases":"Airu Limited; AIRULIMITED","Provider Family":"cloudie.hk","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"386","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AIRULIMITED (cloudie.hk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS208846","ASN Number":"208846","Network Name":"ATOM3-AS LLC \"ATOM3\"","Aliases":"LLC ATOM3; ATOM3-AS","Provider Family":"atom3.com.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-09-23","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"387","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ATOM3-AS (atom3.com.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS209121","ASN Number":"209121","Network Name":"NOVYTSKA-AS LLC BIGNET UKRAINE","Aliases":"liptel.net.ua; NOVYTSKA-AS","Provider Family":"liptel.net.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-07-17","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"388","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NOVYTSKA-AS (liptel.net.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS209274","ASN Number":"209274","Network Name":"Kraken-Network-ISP Kraken Network ISP LTD","Aliases":"Kraken Network ISP LTD; Kraken-Network-ISP","Provider Family":"mortalsoft.online","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-09-13","Network Type":"ISP / network operator","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"389","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Kraken-Network-ISP (mortalsoft.online).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"NL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS209373","ASN Number":"209373","Network Name":"SWISSNET-AS SWISSNET LLC","Aliases":"SWISSNET LLC; SWISSNET-AS","Provider Family":"swissnetwork.io","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"ISP / network operator","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"49","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SWISSNET-AS (swissnetwork.io).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"19","IPsum IPs":"13","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"18","Talos 2024 IPs":"0","Multi-list IPs":"12","Listed-IP Country Mix":"NL:14, CH:5"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS209375","ASN Number":"209375","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"Contrust Solutions S.R.L.; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-15","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"390","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS209396","ASN Number":"209396","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"Contrust Solutions S.R.L.; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-07-22","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"391","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS209413","ASN Number":"209413","Network Name":"DEDIK-CH DEDIK SERVICES LIMITED","Aliases":"DEDIK SERVICES LIMITED; DEDIK-CH","Provider Family":"dedik.io","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"172","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DEDIK-CH (dedik.io).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"8","IPsum IPs":"6","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"7","Talos 2024 IPs":"0","Multi-list IPs":"5","Listed-IP Country Mix":"CH:7, DE:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS209425","ASN Number":"209425","Network Name":"KOI-AS KOI CLOUD SERVICES (Pty) Ltd","Aliases":"KOI CLOUD SERVICES (Pty) Ltd; KOI-AS","Provider Family":"lordvps.net","RIR Country Code":"ZA","Country Name":"South Africa","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"202","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-09","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as KOI-AS (lordvps.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Routing re-verified 2026-10-09: originating 1 IPv4 prefix again on two passes (Not currently originating since 2026-09-29).","Current Community Feed Count":"2","Current Listed IPs":"77","IPsum IPs":"68","IPsum Score >=3":"4","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"63","Talos 2024 IPs":"0","Multi-list IPs":"54","Listed-IP Country Mix":"NL:77"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS209605","ASN Number":"209605","Network Name":"hostbaltic UAB Host Baltic","Aliases":"hostbaltic; Serveroffer; serveroffer.lt; UAB Host Baltic (BtHoster upstream); UAB Host Baltic","Provider Family":"serveroffer.lt","RIR Country Code":"LT","Country Name":"Lithuania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Dedicated-server and VPS hosting; current ASN-DROP","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High: current Spamhaus ASN-DROP","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"140","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, X067, N01, S03","Evidence Summary":"RIPEstat currently sees AS209605 announced. It is in current Spamhaus ASN-DROP. Serveroffer, operated by UAB Host Baltic, publicly offers dedicated servers and VPS. Feed inclusion does not imply every tenant is malicious. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as hostbaltic (serveroffer.lt).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Active current ASN-DROP network with direct VPS and dedicated-server services.","Current Community Feed Count":"2","Current Listed IPs":"120","IPsum IPs":"84","IPsum Score >=3":"14","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"86","Talos 2024 IPs":"0","Multi-list IPs":"50","Listed-IP Country Mix":"LT:120"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS209847","ASN Number":"209847","Network Name":"THE WorkTitans B.V.","Aliases":"THE.Hosting; PQ.Hosting successor; Stark successor; THE; WorkTitans B.V.","Provider Family":"Stark / PQ.Hosting / THE.Hosting / UFO","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Bulletproof / high-risk hosting family","Category":"Sanctioned threat-activity-enabler successor (active)","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"127","Login / Identity Evidence":"No","Actor / Campaign":"Russian state-sponsored operations; Iranian state-sponsored operations; DPRK operations; Chinese state-sponsored operations; cybercrime infrastructure","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S12, S13, N01, S03","Evidence Summary":"Recorded Future documented AS209847 as a newly created network for THE.Hosting, the brand succeeding PQ.Hosting/Stark Industries, and assessed continued operation despite sanctions and ownership changes. Research tracks AS44477 through PQ.Hosting/THE.Hosting changes, creation of AS209847 and Russian infrastructure migration to AS33993. AS209847 and AS33993 are in current ASN-DROP; AS44477 is currently unannounced. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as THE (stark-industries.solutions).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. High for infrastructure continuity; provider is best treated as a sanctioned threat-actor enabler/successor rather than proof every hosted workload is malicious. Active and announcing routes as WorkTitans B.V. on 2026-09-15; present in the current Spamhaus ASN-DROP snapshot.","Current Community Feed Count":"1","Current Listed IPs":"4","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"4","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"FI:3, TR:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS209868","ASN Number":"209868","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"Contrust Solutions S.R.L.; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-07-27","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"392","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS209883","ASN Number":"209883","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"Contrust Solutions S.R.L.; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"82","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"3","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"DE:3"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS209889","ASN Number":"209889","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-06-05","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"393","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS209896","ASN Number":"209896","Network Name":"LexistarAllianceLTD Contrust Solutions S.R.L.","Aliases":"Contrust Solutions S.R.L.; LexistarAllianceLTD","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-10-05","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"116","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-07","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as LexistarAllianceLTD (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"US:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS209944","ASN Number":"209944","Network Name":"EJX Contrust Solutions S.R.L.","Aliases":"Contrust Solutions S.R.L.; EJX","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"146","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as EJX (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS209946","ASN Number":"209946","Network Name":"ALINDA-AS ALINDA LLC","Aliases":"ALINDA LLC; ALINDA-AS","Provider Family":"altawk.com","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-10-02","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"394","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-07","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ALINDA-AS (altawk.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Routing re-verified 2026-10-02: origination resumed after the dormant period recorded in the previous snapshot. RIR object remains active. ASN-DROP membership unchanged, so tier and enablement are unchanged.","Current Community Feed Count":"3","Current Listed IPs":"30","IPsum IPs":"9","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"3","Data-Shield IPs":"22","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"DE:12, FI:10, NL:3, SE:3, CZ:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS209961","ASN Number":"209961","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-07-01","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"395","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS209963","ASN Number":"209963","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-05-19","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"396","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS209982","ASN Number":"209982","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"Contrust Solutions S.R.L.; Contrust-Solutions","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-22","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"397","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS210006","ASN Number":"210006","Network Name":"ASKZ Shereverov Marat Ahmedovich","Aliases":"Shereverov Marat Ahmedovich; ASKZ","Provider Family":"shereverov.marat","RIR Country Code":"KZ","Country Name":"Kazakhstan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"76","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ASKZ (shereverov.marat).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"267","IPsum IPs":"263","IPsum Score >=3":"7","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"25","Talos 2024 IPs":"0","Multi-list IPs":"21","Listed-IP Country Mix":"KZ:256, NL:10, GB:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS210240","ASN Number":"210240","Network Name":"NTC-AS New Communication Technologies LLC","Aliases":"New Communication Technologies LLC; NTC-AS","Provider Family":"nts.center","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"58","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NTC-AS (nts.center).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"RU:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS210316","ASN Number":"210316","Network Name":"ELEKOMS-AS CJSC \"SCIENTIFIC AND PRODUCTION FIRM \"ELEKOMS\"\"","Aliases":"CJSC SCIENTIFIC AND PRODUCTION FIRM ELEK; ELEKOMS-AS","Provider Family":"elekoms.net.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"398","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ELEKOMS-AS (elekoms.net.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS210457","ASN Number":"210457","Network Name":"KYONIX Kyonix Networks Limited","Aliases":"Kyonix Networks Limited; KYONIX","Provider Family":"kyonix.com","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"7","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as KYONIX (kyonix.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"6","IPsum IPs":"4","IPsum Score >=3":"3","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"5","Talos 2024 IPs":"0","Multi-list IPs":"3","Listed-IP Country Mix":"DE:6"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS210530","ASN Number":"210530","Network Name":"ip2con IP Connect Inc","Aliases":"IP Connect Inc; ip2con","Provider Family":"ipconnect.services","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"174","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ip2con (ipconnect.services).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS210546","ASN Number":"210546","Network Name":"CHSL-ONE CHSL ONE LTD","Aliases":"CHSL ONE LTD; CHSL-ONE","Provider Family":"chosting.solutions","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"4","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CHSL-ONE (chosting.solutions).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"48","IPsum IPs":"23","IPsum Score >=3":"4","IPsum Score >=5":"3","Open-Proxy IPs":"20","Data-Shield IPs":"15","Talos 2024 IPs":"0","Multi-list IPs":"9","Listed-IP Country Mix":"DE:39, FI:8, RU:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS210558","ASN Number":"210558","Network Name":"services-1337-gmbh 1337 Services GmbH","Aliases":"1337 Services GmbH; services-1337-gmbh","Provider Family":"as210558.net","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"15","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as services-1337-gmbh (as210558.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"99","IPsum IPs":"40","IPsum Score >=3":"7","IPsum Score >=5":"0","Open-Proxy IPs":"2","Data-Shield IPs":"78","Talos 2024 IPs":"14","Multi-list IPs":"35","Listed-IP Country Mix":"NL:36, PL:23, DE:20, US:17, HK:3"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS210644","ASN Number":"210644","Network Name":"AEZA-AS AEZA GROUP LLC","Aliases":"Aeza; AEZA-AS; AEZA GROUP LLC; Aéza International Limited","Provider Family":"Aeza Group","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Bulletproof / high-risk hosting family","Category":"Source-confirmed sanctioned BPH (active)","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"30","Login / Identity Evidence":"No","Actor / Campaign":"Meduza Stealer; Lumma Stealer; BianLian; RedLine Stealer; BlackSprut; Doppelgänger; DDoSia","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S09, S14, N01, S03","Evidence Summary":"Silent Push identifies AS210644 as Aeza bulletproof-hosting infrastructure and documents post-sanctions route migration to Hypercore. U.S. Treasury separately designated Aeza Group for providing BPH to infostealers, ransomware actors and illicit markets. OFAC designated Aeza Group as a bulletproof hosting provider. Technical research maps the family to AS210644 and AS216246; both are in current ASN-DROP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AEZA-AS (aeza.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. High: the ASN-to-provider mapping is explicit and the provider itself was sanctioned as BPH; this is provider-level evidence, not merely one malicious tenant. Active and announcing routes as Aéza International Limited on 2026-09-15; also present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Revalidate holder and announcements before enforcement.","Current Community Feed Count":"3","Current Listed IPs":"180","IPsum IPs":"63","IPsum Score >=3":"1","IPsum Score >=5":"1","Open-Proxy IPs":"110","Data-Shield IPs":"20","Talos 2024 IPs":"2","Multi-list IPs":"15","Listed-IP Country Mix":"SE:65, DE:36, NL:36, FI:21, AT:14, FR:6, GB:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS210654","ASN Number":"210654","Network Name":"CUSTOMER-AS Des Capital B.V.","Aliases":"Des Capital B.V.; CUSTOMER-AS","Provider Family":"serverion.com","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"132","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CUSTOMER-AS (serverion.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS210703","ASN Number":"210703","Network Name":"FIRSTBYTE-AS FIRSTBYTE HOSTING LTD","Aliases":"almaseabi.net; FIRSTBYTE-AS","Provider Family":"almaseabi.net","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-04-17","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"399","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as FIRSTBYTE-AS (almaseabi.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS210705","ASN Number":"210705","Network Name":"AliMonfared Ali Monfared","Aliases":"Ali Monfared; AliMonfared","Provider Family":"rapidoserver.com","RIR Country Code":"IR","Country Name":"Iran","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"178","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AliMonfared (rapidoserver.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS210707","ASN Number":"210707","Network Name":"Company Dadeh Pardazesh Boroumand Kerman co. LLC","Aliases":"Dadeh Pardazesh Boroumand Kerman co. LLC; Company","Provider Family":"dadeh-pardazesh-boroumand-kerman","RIR Country Code":"IR","Country Name":"Iran","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-08-22","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"400","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Company (dadeh-pardazesh-boroumand-kerman).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS210714","ASN Number":"210714","Network Name":"WORLD-NET-ISP-Provider Orhan Turkan","Aliases":"Orhan Turkan; WORLD-NET-ISP-Provider","Provider Family":"eksenbilisim.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"ISP / network operator","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"85","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as WORLD-NET-ISP-Provider (eksenbilisim.com.tr).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS210848","ASN Number":"210848","Network Name":"TK-NET Telkom Internet LTD","Aliases":"Telkom Internet LTD; TK-NET","Provider Family":"server-panel.org","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"46","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as TK-NET (server-panel.org).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"AZ:1, SC:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS210950","ASN Number":"210950","Network Name":"ERISHENNYA-ASN TOV E-RISHENNYA","Aliases":"erishennya; ERISHENNYA-ASN","Provider Family":"erishennya","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-03-06","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"401","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ERISHENNYA-ASN (erishennya).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS211066","ASN Number":"211066","Network Name":"RYZEHOSTING-TRADING Simon Mariacher","Aliases":"Simon Mariacher; RYZEHOSTING-TRADING","Provider Family":"ryzehosting.com","RIR Country Code":"AT","Country Name":"Austria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"24","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as RYZEHOSTING-TRADING (ryzehosting.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"NL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS211121","ASN Number":"211121","Network Name":"India Tiger Network Limited","Aliases":"Tiger Network Limited; India","Provider Family":"imtigernet","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"402","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as India (imtigernet).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS211199","ASN Number":"211199","Network Name":"LIPTEL-AS LLC BIGNET UKRAINE","Aliases":"liptel.net.ua; LIPTEL-AS","Provider Family":"liptel.net.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-08-12","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"403","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as LIPTEL-AS (liptel.net.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS211238","ASN Number":"211238","Network Name":"DCYBER Dedicated Cyber Limited","Aliases":"Dedicated Cyber Limited; DCYBER","Provider Family":"zumy.eu","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"142","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DCYBER (zumy.eu).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS211663","ASN Number":"211663","Network Name":"GALEON-AS GALEON LLC","Aliases":"Bearhost-linked; changway.hk feed lineage; GALEON-AS; GALEON LLC","Provider Family":"Bearhost-linked","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Bulletproof / high-risk hosting family","Category":"Source-confirmed BPH (active)","Evidence Level":"High","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"56","Login / Identity Evidence":"No","Actor / Campaign":"Bearhost bulletproof-hosting ecosystem","Last Evidence":"2026-09-29","Source IDs":"S01, S02, X072, N01, S03","Evidence Summary":"Spamhaus linked AS211663 to the Bearhost threat actor's BPH return and placed it in DROP/ASN-DROP. The live ASN-DROP feed currently associates it with changway.hk. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as GALEON-AS (changway.hk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. High: direct BPH/operator linkage by Spamhaus and current block-feed inclusion. Active and announcing routes as GALEON LLC on 2026-09-15; present in current ASN-DROP.","Current Community Feed Count":"2","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"RU:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS211720","ASN Number":"211720","Network Name":"DATASHIELD_CH Datashield, Inc.","Aliases":"Datashield, Inc.; DATASHIELD_CH","Provider Family":"xor.sc","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"182","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DATASHIELD_CH (xor.sc).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"7","IPsum IPs":"6","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"4","Talos 2024 IPs":"1","Multi-list IPs":"4","Listed-IP Country Mix":"SC:4, CH:3"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS211762","ASN Number":"211762","Network Name":"REGION40 Region40 LLC","Aliases":"fineproxy.org; REGION40","Provider Family":"fineproxy.org","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2024-08-22","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"405","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as REGION40 (fineproxy.org).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS211860","ASN Number":"211860","Network Name":"VPSDEDIC-AS Nerushenko Vyacheslav Nikolaevich","Aliases":"Nerushenko Vyacheslav Nikolaevich; VPSDEDIC-AS","Provider Family":"vpsdedic.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"72","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as VPSDEDIC-AS (vpsdedic.ru).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"12","IPsum IPs":"10","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"9","Talos 2024 IPs":"0","Multi-list IPs":"7","Listed-IP Country Mix":"GB:7, RU:5"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS211922","ASN Number":"211922","Network Name":"IPDISTR IP Connect Inc","Aliases":"IP Connect Inc; IPDISTR","Provider Family":"ipconnect.services","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"79","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as IPDISTR (ipconnect.services).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS211955","ASN Number":"211955","Network Name":"NOTBADHOSTING NOTBAD HOSTING LTD","Aliases":"NOTBAD HOSTING LTD; NOTBADHOSTING","Provider Family":"notbad.cloud","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"118","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NOTBADHOSTING (notbad.cloud).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"DE:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS212017","ASN Number":"212017","Network Name":"CUBILLO Gerardo Cubillo Torralba Empresa Constructora S.L","Aliases":"Gerardo Cubillo Torralba Empresa Constru; CUBILLO","Provider Family":"cubilloconstrucciones.com","RIR Country Code":"ES","Country Name":"Spain","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-05-18","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"406","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CUBILLO (cubilloconstrucciones.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS212283","ASN Number":"212283","Network Name":"ROZA-AS ROZA HOLIDAYS EOOD","Aliases":"ROZA HOLIDAYS EOOD; ROZA-AS","Provider Family":"rosa-holidays.com","RIR Country Code":"BG","Country Name":"Bulgaria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-04-20","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"407","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ROZA-AS (rosa-holidays.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS212448","ASN Number":"212448","Network Name":"turkbil Turkbil Teknoloji Ltd. Sti.","Aliases":"turkbil.com.tr; turkbil","Provider Family":"turkbil.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2024-04-08","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"408","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as turkbil (turkbil.com.tr).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS212622","ASN Number":"212622","Network Name":"LIVECOMM-AS LIVE COMM LLC","Aliases":"LIVE COMM LLC; LIVECOMM-AS","Provider Family":"livecomm","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"409","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as LIVECOMM-AS (livecomm).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS212651","ASN Number":"212651","Network Name":"D-CONECT-AS D-CONECT LLC","Aliases":"D-CONECT LLC; D-CONECT-AS","Provider Family":"d-conect","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"186","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as D-CONECT-AS (d-conect).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS212666","ASN Number":"212666","Network Name":"ipv4-net Sabire Irmak Mala","Aliases":"Sabire Irmak Mala; ipv4-net","Provider Family":"eksenbilisim.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-02-07","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"410","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ipv4-net (eksenbilisim.com.tr).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS212867","ASN Number":"212867","Network Name":"SIPALTO Sipalto Ltd","Aliases":"brutalproxies.com; SIPALTO","Provider Family":"brutalproxies.com","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2020-11-22","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"411","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SIPALTO (brutalproxies.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS213035","ASN Number":"213035","Network Name":"AS-SERVERION Des Capital B.V.","Aliases":"Des Capital B.V.; AS-SERVERION","Provider Family":"serverion.com","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"129","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AS-SERVERION (serverion.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"3","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"NL:3"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS213137","ASN Number":"213137","Network Name":"Contrust Contrust Solutions S.R.L.","Aliases":"kontrast.md; Contrust","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-24","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"412","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS213200","ASN Number":"213200","Network Name":"FZink Ferdinand Zink trading as Tube-Hosting","Aliases":"Ferdinand Zink trading as Tube-Hosting; FZink","Provider Family":"tube-hosting.de","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"43","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as FZink (tube-hosting.de).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"NL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS213373","ASN Number":"213373","Network Name":"IPCONNECT IP Connect Inc","Aliases":"IP Connect Inc; IPCONNECT","Provider Family":"ipconnect.services","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"11","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as IPCONNECT (ipconnect.services).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"10","IPsum IPs":"9","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"NL:10"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS213388","ASN Number":"213388","Network Name":"IIC-AS IIC RAIL LIMITED","Aliases":"IIC RAIL LIMITED; IIC-AS","Provider Family":"iic-rail","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"90","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as IIC-AS (iic-rail).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"13","IPsum IPs":"8","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"12","Talos 2024 IPs":"0","Multi-list IPs":"7","Listed-IP Country Mix":"GB:13"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS213389","ASN Number":"213389","Network Name":"ASPODOLSK Podolskie opticheskie seti Ltd.","Aliases":"Podolskie opticheskie seti Ltd.; ASPODOLSK","Provider Family":"netip.com.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"190","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ASPODOLSK (netip.com.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS213438","ASN Number":"213438","Network Name":"colocatel-inc ColocaTel Inc.","Aliases":"ColocaTel Inc.; colocatel-inc","Provider Family":"colocatel.com","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"31","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as colocatel-inc (colocatel.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"17","IPsum IPs":"14","IPsum Score >=3":"2","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"8","Talos 2024 IPs":"1","Multi-list IPs":"6","Listed-IP Country Mix":"NL:16, DE:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS213441","ASN Number":"213441","Network Name":"SLAYER-AS SLAYER GROUP LIMITED","Aliases":"SLAYER GROUP LIMITED; SLAYER-AS","Provider Family":"slayergroup.ltd","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"413","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SLAYER-AS (slayergroup.ltd).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS213652","ASN Number":"213652","Network Name":"Sunucun-Cloud Sunucun Bilgi Iletisim Teknolojileri ve Ticaret Ltd. Sti.","Aliases":"Sunucun Bilgi Iletisim Teknolojileri ve; Sunucun-Cloud","Provider Family":"sunucun.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"201","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Sunucun-Cloud (sunucun.com.tr).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"TR:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS213702","ASN Number":"213702","Network Name":"QWINS-LTD QWINS LTD","Aliases":"QWINS LTD; QWINS-LTD","Provider Family":"qwins.co","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"144","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as QWINS-LTD (qwins.co).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"21","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"3","Talos 2024 IPs":"16","Multi-list IPs":"1","Listed-IP Country Mix":"EE:16, DE:4, SC:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS213753","ASN Number":"213753","Network Name":"interedge InterEdge B.V.","Aliases":"InterEdge B.V.; interedge","Provider Family":"serverion.com","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"199","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as interedge (serverion.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS213790","ASN Number":"213790","Network Name":"LimitedNetwork-AS Limited Network LTD","Aliases":"Limited Network LTD; LimitedNetwork-AS","Provider Family":"btcloud.ro","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"115","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as LimitedNetwork-AS (btcloud.ro).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"140","IPsum IPs":"80","IPsum Score >=3":"36","IPsum Score >=5":"10","Open-Proxy IPs":"0","Data-Shield IPs":"134","Talos 2024 IPs":"0","Multi-list IPs":"74","Listed-IP Country Mix":"GB:75, DE:35, NL:30"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS213897","ASN Number":"213897","Network Name":"BUBBLES-AS BUBBLES ALTER LIMITED","Aliases":"BUBBLES ALTER LIMITED; BUBBLES-AS","Provider Family":"bubblesalter","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"415","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BUBBLES-AS (bubblesalter).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS213921","ASN Number":"213921","Network Name":"DA-MOTORS-AS DAVID ASCOTT MOTORS LTD","Aliases":"DAVID ASCOTT MOTORS LTD; DA-MOTORS-AS","Provider Family":"davidascottmotorsltd","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-09-29","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"184","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DA-MOTORS-AS (davidascottmotorsltd).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS213995","ASN Number":"213995","Network Name":"FROSTYHOSTING-AS Belenkii Ivan Alexandrovich","Aliases":"Belenkii Ivan Alexandrovich; FROSTYHOSTING-AS","Provider Family":"frostyhosting","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"148","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as FROSTYHOSTING-AS (frostyhosting).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS214018","ASN Number":"214018","Network Name":"IIC-AS INTERNET INTELLIGENCE COMPANY LTD","Aliases":"INTERNET INTELLIGENCE COMPANY LTD; IIC-AS","Provider Family":"intintell.co.uk","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"417","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as IIC-AS (intintell.co.uk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS214351","ASN Number":"214351","Network Name":"FEMOIT FEMO IT SOLUTIONS LIMITED","Aliases":"Femo IT Solutions; Defhost-linked; FEMOIT; Defhost-associated; FEMO IT SOLUTIONS LIMITED","Provider Family":"Femo IT Solutions","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Bulletproof / high-risk hosting family","Category":"Source-confirmed BPH (active)","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"109","Login / Identity Evidence":"No","Actor / Campaign":"Cobalt Strike; DcRat; Rhadamanthys; TinyLoader; THC Hydra; Amadey; QuasarRAT; RedLine Stealer; REMCOS; Stealc; SystemBC; SvcStealer; CastleLoader","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, X003, X031, N01, S03","Evidence Summary":"Recorded Future assessed with high confidence that AS214351 is controlled by Defhost, a service that openly markets resilience to governments, regulators and Spamhaus. The report observed numerous malware and C2 families in its space. AS214351 is in live Spamhaus ASN-DROP. Recorded Future found one of the highest validated-malicious-infrastructure concentrations relative to size, including Cobalt Strike, DcRat, Rhadamanthys, TinyLoader and THC Hydra C2, and assessed with high confidence that Femo is controlled by Defhost, which advertises abuse-resistant VDS. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as FEMOIT (as214351.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Multiple independent high-confidence sources support aggressive treatment while the ASN remains assigned/listed. High: provider-control assessment, abuse-resilience marketing, multiple independent malware families, and current ASN-DROP inclusion collectively exceed one-off rental evidence. Active and announcing routes as FEMO IT SOLUTIONS LIMITED on 2026-09-15; present in the current Spamhaus ASN-DROP snapshot.","Current Community Feed Count":"1","Current Listed IPs":"3","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"DE:3"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS214357","ASN Number":"214357","Network Name":"First-Host Abdolmajid Mashayekhi","Aliases":"almaseabi.net; First-Host","Provider Family":"almaseabi.net","RIR Country Code":"IR","Country Name":"Iran","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-07-15","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"418","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as First-Host (almaseabi.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS214422","ASN Number":"214422","Network Name":"NET67X Dmytro Nebaba","Aliases":"Dmytro Nebaba; NET67X","Provider Family":"qwins.co","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-08-24","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"419","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NET67X (qwins.co).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS214497","ASN Number":"214497","Network Name":"WHITELABEL Whitelabel Solutions, Ltd.","Aliases":"Whitelabel Solutions; whitelabel.sh; WHITELABEL; Whitelabel Solutions, Ltd.","Provider Family":"whitelabel.sh","RIR Country Code":"IL","Country Name":"Israel","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Whitelabel hosting, transit and BYOIP infrastructure","Category":"Current Spamhaus ASN-DROP","Evidence Level":"Strong","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"420","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, X004, N01, S03","Evidence Summary":"AS214497 is in the live Spamhaus ASN-DROP feed. Spamhaus reserves DROP for networks investigators assess as controlled by cybercrime operations or bulletproof hosters. Excedo also places Whitelabel Solutions in a layered ASN/BPH chain. This supports blocking while listed, without independently proving every nominal company actor is complicit. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as WHITELABEL (whitelabel.sh).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current high-confidence ASN-DROP membership warrants blocking, provided the feed is refreshed daily so a delisting or reassignment is honored.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS214576","ASN Number":"214576","Network Name":"BRM5-AS Berdiev Ruslan Mukhabatovich","Aliases":"Berdiev Ruslan Mukhabatovich; BRM5-AS","Provider Family":"berdiev-ruslan-mukhabatovich","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-07-01","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"421","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BRM5-AS (berdiev-ruslan-mukhabatovich).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS214927","ASN Number":"214927","Network Name":"PSB-AS PSB HOSTING LTD","Aliases":"PSB HOSTING LTD; PSB-AS","Provider Family":"psb.hosting","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"94","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as PSB-AS (psb.hosting).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"NL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS215117","ASN Number":"215117","Network Name":"HOSTERDADDY HosterDaddy Private Limited","Aliases":"HosterDaddy Private Limited; HOSTERDADDY","Provider Family":"hosterdaddy.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"131","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as HOSTERDADDY (hosterdaddy.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"6","IPsum IPs":"6","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"IN:6"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS215136","ASN Number":"215136","Network Name":"Ryzehosting Finn Hess trading as Ryzehosting","Aliases":"Finn Hess trading as Ryzehosting; Ryzehosting","Provider Family":"ryzehosting.com","RIR Country Code":"AT","Country Name":"Austria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"20","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Ryzehosting (ryzehosting.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"NL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS215183","ASN Number":"215183","Network Name":"zhaikov-as ZHAIKOV AITOLKYN BEKBOLATKYZY","Aliases":"ZHAIKOV AITOLKYN BEKBOLATKYZY; zhaikov-as","Provider Family":"vaultdweller.net","RIR Country Code":"KZ","Country Name":"Kazakhstan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-11-12","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"422","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as zhaikov-as (vaultdweller.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS215310","ASN Number":"215310","Network Name":"USERCLOUD Pfcloud UG (haftungsbeschrankt)","Aliases":"Pfcloud UG (haftungsbeschrankt); USERCLOUD","Provider Family":"pfcloud.io","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"423","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as USERCLOUD (pfcloud.io).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS215311","ASN Number":"215311","Network Name":"REGXA-CLOUD Regxa Company for Information Technology Ltd","Aliases":"Regxa Company for Information Technology; REGXA-CLOUD","Provider Family":"regxa.iq","RIR Country Code":"IQ","Country Name":"Iraq","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"122","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as REGXA-CLOUD (regxa.iq).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"6","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"4","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"DE:4, GB:1, IQ:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS215340","ASN Number":"215340","Network Name":"MySim-Nigeria Huize Telecom Limited","Aliases":"Huize Telecom Limited; MySim-Nigeria","Provider Family":"62yun.com","RIR Country Code":"NG","Country Name":"Nigeria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"424","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as MySim-Nigeria (62yun.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS215376","ASN Number":"215376","Network Name":"mlcloud ML Cloud Ltd","Aliases":"ML Cloud Ltd; mlcloud","Provider Family":"sshvps.net","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"425","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as mlcloud (sshvps.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS215402","ASN Number":"215402","Network Name":"ASAD-AS Asadov Ruslan Rafaelevich","Aliases":"Asadov Ruslan Rafaelevich; ASAD-AS","Provider Family":"berdiev-ruslan-mukhabatovich","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"123","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ASAD-AS (berdiev-ruslan-mukhabatovich).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS215460","ASN Number":"215460","Network Name":"FELCLOUD Daniel Mishayev","Aliases":"Daniel Mishayev; FELCLOUD","Provider Family":"infiniroute.io","RIR Country Code":"IL","Country Name":"Israel","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"426","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as FELCLOUD (infiniroute.io).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS215474","ASN Number":"215474","Network Name":"BIIL-RU-AS BIIL RU LTD","Aliases":"biil.ru; BIIL-RU-AS","Provider Family":"biil.ru","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-02-13","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"428","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BIIL-RU-AS (biil.ru).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS215730","ASN Number":"215730","Network Name":"H2NEXUS-AS H2NEXUS CLOUD SERVICES - FZCO","Aliases":"H2NEXUS CLOUD SERVICES - FZCO; H2NEXUS-AS","Provider Family":"h2.nexus","RIR Country Code":"AE","Country Name":"United Arab Emirates","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"8","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as H2NEXUS-AS (h2.nexus).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"26","IPsum IPs":"15","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"6","Data-Shield IPs":"11","Talos 2024 IPs":"0","Multi-list IPs":"6","Listed-IP Country Mix":"DE:17, FI:4, ES:2, PL:2, BY:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS215731","ASN Number":"215731","Network Name":"NovusLabs Novus Labs Limited","Aliases":"Novus Labs Limited; NovusLabs","Provider Family":"novuslabslimited.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"429","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NovusLabs (novuslabslimited.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS215765","ASN Number":"215765","Network Name":"RADIO-LINK-SMART \"RADIO-LINK SMART\" LLC","Aliases":"RADIO-LINK SMART LLC; RADIO-LINK-SMART","Provider Family":"pitline.net","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"193","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as RADIO-LINK-SMART (pitline.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS215925","ASN Number":"215925","Network Name":"VPSVAULTHOST VPSVAULT.HOST LTD","Aliases":"VPSVAULT.HOST LTD; VPSVAULTHOST","Provider Family":"vpsvault.host","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"100","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as VPSVAULTHOST (vpsvault.host).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"333","IPsum IPs":"279","IPsum Score >=3":"14","IPsum Score >=5":"5","Open-Proxy IPs":"0","Data-Shield IPs":"109","Talos 2024 IPs":"0","Multi-list IPs":"55","Listed-IP Country Mix":"SE:256, SC:29, CA:27, BR:20, RU:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS215930","ASN Number":"215930","Network Name":"COD CIPHER OPERATIONS DOO BEOGRAD - NOVI BEOGRAD","Aliases":"CIPHER OPERATIONS DOO BEOGRAD - NOVI BEO; COD","Provider Family":"almaseabi.net","RIR Country Code":"RS","Country Name":"Serbia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"107","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as COD (almaseabi.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"41","IPsum IPs":"23","IPsum Score >=3":"11","IPsum Score >=5":"3","Open-Proxy IPs":"0","Data-Shield IPs":"40","Talos 2024 IPs":"0","Multi-list IPs":"22","Listed-IP Country Mix":"GB:41"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS216078","ASN Number":"216078","Network Name":"KREMER-AS Liam Kremer","Aliases":"Liam Kremer; KREMER-AS","Provider Family":"snowcore.io","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"171","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as KREMER-AS (snowcore.io).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS216127","ASN Number":"216127","Network Name":"NUXT-AS INTERNATIONAL HOSTING COMPANY LIMITED","Aliases":"INTERNATIONAL HOSTING COMPANY LIMITED; NUXT-AS","Provider Family":"nuxt.cloud","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"3","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NUXT-AS (nuxt.cloud).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"22","IPsum IPs":"7","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"7","Data-Shield IPs":"12","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"DE:18, FI:3, RU:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS216246","ASN Number":"216246","Network Name":"RU-AEZA-AS Aeza Group LLC","Aliases":"Aeza; RU-AEZA-AS; Aeza Group LLC","Provider Family":"Aeza Group","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Bulletproof / high-risk hosting family","Category":"Source-confirmed sanctioned BPH (active)","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"91","Login / Identity Evidence":"No","Actor / Campaign":"Meduza Stealer; Lumma Stealer; BianLian; RedLine Stealer; BlackSprut","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S09, S14, N01, S03","Evidence Summary":"Silent Push explicitly maps AS216246 to Aeza Group and calls Aeza a sanctioned BPH provider. Treasury described Aeza as supplying infrastructure to malware, ransomware and illicit-drug-market operators. OFAC designated Aeza Group as a bulletproof hosting provider. Technical research maps the family to AS210644 and AS216246; both are in current ASN-DROP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as RU-AEZA-AS (aeza.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. High: explicit ASN mapping plus government provider-level sanctions designation. Active and announcing routes as Aeza Group LLC on 2026-09-15; also present in the current Spamhaus ASN-DROP snapshot.","Current Community Feed Count":"2","Current Listed IPs":"21","IPsum IPs":"15","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"7","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"RU:19, US:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS216378","ASN Number":"216378","Network Name":"NETGATE-COMUNICATIONS-AS Net Gate Telecom S.R.L.","Aliases":"Net Gate Telecom S.R.L.; NETGATE-COMUNICATIONS-AS","Provider Family":"net-gate.ro","RIR Country Code":"RO","Country Name":"Romania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-09-28","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"430","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NETGATE-COMUNICATIONS-AS (net-gate.ro).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS216475","ASN Number":"216475","Network Name":"nktelecom NKtelecom INC","Aliases":"NKtelecom INC; nktelecom","Provider Family":"nktele.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"ISP / network operator","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"6","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as nktelecom (nktele.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"3","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"NL:2, US:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS218731","ASN Number":"218731","Network Name":"Andris-Jakovlevs Andris Jakovlevs","Aliases":"Andris-Jakovlevs","Provider Family":"qwins.co","RIR Country Code":"LV","Country Name":"Latvia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"52","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Andris-Jakovlevs (qwins.co).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS218732","ASN Number":"218732","Network Name":"rapidoserver Sajjad Khazaei","Aliases":"rapidoserver","Provider Family":"rapidoserver.com","RIR Country Code":"IR","Country Name":"Iran","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate identity, device, session, event-country, and post-authentication activity; review dependencies before deny actions.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"21","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S03, N01","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as rapidoserver (rapidoserver.com). Current routing and RIR registration were independently refreshed.","Analyst Notes":"Current feed membership is a high-confidence network-risk signal, not proof that every address, tenant, or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS218986","ASN Number":"218986","Network Name":"SnowcoreInc Snowcore Inc","Aliases":"Snowcore Inc; SnowcoreInc","Provider Family":"snowcore.io","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"48","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SnowcoreInc (snowcore.io).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"NL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS219067","ASN Number":"219067","Network Name":"CHIARA-AS Chiara Conti","Aliases":"CHIARA-AS; eggywall.org; Chiara Conti","Provider Family":"CHIARA-AS","RIR Country Code":"IT","Country Name":"Italy","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Bulletproof / high-risk hosting family","Category":"Current malicious prefix-hopping network","Evidence Level":"High","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"22","Login / Identity Evidence":"No","Actor / Campaign":"Roblox credential phishing; prefix hopping","Last Evidence":"2026-09-29","Source IDs":"S01, S02, X074, N01, S03","Evidence Summary":"Spamhaus tied AS219067's sole prefix to Roblox phishing, documented deliberate prefix-hopping behavior, and placed the network in SBL/DROP. This is strong malicious-network evidence but not a generalized BPH-provider attribution. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CHIARA-AS (eggywall.org).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. High for current malicious operation; category intentionally avoids claiming a broader BPH service without evidence. Active and announcing routes as Chiara Conti/CHIARA-AS on 2026-09-15; present in current ASN-DROP.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS219326","ASN Number":"219326","Network Name":"SULAVIL SULAVI LTD","Aliases":"SULAVI LTD; SULAVIL","Provider Family":"sulavi.co.uk","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"74","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SULAVIL (sulavi.co.uk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"261","IPsum IPs":"261","IPsum Score >=3":"105","IPsum Score >=5":"0","Open-Proxy IPs":"2","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"5","Listed-IP Country Mix":"NL:261"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS219502","ASN Number":"219502","Network Name":"STORMCLOUD-AS Storm Industries LLC","Aliases":"Storm Industries LLC; STORMCLOUD-AS","Provider Family":"stormindustries.llc","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"103","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as STORMCLOUD-AS (stormindustries.llc).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"279","IPsum IPs":"270","IPsum Score >=3":"40","IPsum Score >=5":"8","Open-Proxy IPs":"0","Data-Shield IPs":"118","Talos 2024 IPs":"0","Multi-list IPs":"109","Listed-IP Country Mix":"NL:279"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS266702","ASN Number":"266702","Network Name":"AS266702 - MEGALINK S.R.L.","Aliases":"MEGALINK S.R.L.; MEGALINK_S.R.L.","Provider Family":"nodonorte.net.ar","RIR Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"105","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as MEGALINK_S.R.L. (nodonorte.net.ar).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"16","IPsum IPs":"11","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"10","Talos 2024 IPs":"0","Multi-list IPs":"5","Listed-IP Country Mix":"AR:16"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS266724","ASN Number":"266724","Network Name":"AS266724 - MYRIAM PILAR ESCOBAR VEGA (DON SERVER)","Aliases":"MYRIAM PILAR ESCOBAR VEGA (DON SERVER); MYRIAM_PILAR_ESCOBAR_VEGA_(DON_SERVER)","Provider Family":"donserver.cl","RIR Country Code":"CL","Country Name":"Chile","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-12-18","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"431","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as MYRIAM_PILAR_ESCOBAR_VEGA_(DON_SERVER) (donserver.cl).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS327837","ASN Number":"327837","Network Name":"SEYCHELLES INTERNET EXCHANGE POINT ASSOCIATION - SEYCHELLES INTERNET EXCHANGE POINT ASSOCIATION","Aliases":"seyix.sc; SEY-IX-MANAGEMENT","Provider Family":"seyix.sc","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"afrinic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"432","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SEY-IX-MANAGEMENT (seyix.sc).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS327952","ASN Number":"327952","Network Name":"NATCOM Development and Investment Limited - NATCOM Development and Investment Limited","Aliases":"ntel.com.ng; AS-NATCOM","Provider Family":"ntel.com.ng","RIR Country Code":"NG","Country Name":"Nigeria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"afrinic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-02-06","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"433","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AS-NATCOM (ntel.com.ng).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS328095","ASN Number":"328095","Network Name":"BLUEGATE EXCHANGE - BLUEGATE EXCHANGE","Aliases":"bluegate-exchange.co.za; BLUEGATE-EXCHANGE-AS","Provider Family":"bluegate-exchange.co.za","RIR Country Code":"ZA","Country Name":"South Africa","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"afrinic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2020-01-02","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"434","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BLUEGATE-EXCHANGE-AS (bluegate-exchange.co.za).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS328819","ASN Number":"328819","Network Name":"Bluecentrix PTY LTD - Bluecentrix PTY LTD","Aliases":"Bluecentrix PTY LTD; BPL-AS","Provider Family":"bluecentrix.co.za","RIR Country Code":"ZA","Country Name":"South Africa","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"afrinic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-11-24","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"435","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BPL-AS (bluecentrix.co.za).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS328958","ASN Number":"328958","Network Name":"cybrscrb ltd. - cybrscrb ltd.","Aliases":"cybrscrb.com; CL21-AS","Provider Family":"cybrscrb.com","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"afrinic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2024-05-26","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"436","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CL21-AS (cybrscrb.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS329007","ASN Number":"329007","Network Name":"ELENDE - TECNOLOGIAS DE INFORMACAO - COMERCIO E SERVICOS, LDA - ELENDE - TECNOLOGIAS DE INFORMACAO - COMERCIO E SERVICOS, LDA","Aliases":"ELENDE - TECNOLOGIAS DE INFORMACAO - COM; ELENDE","Provider Family":"elende.ao","RIR Country Code":"AO","Country Name":"Angola","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"afrinic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"149","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ELENDE (elende.ao).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"1","Current Listed IPs":"2","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"AO:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS394082","ASN Number":"394082","Network Name":"GOOGLE-PEER - rootcloud LLC","Aliases":"rootcloud LLC; GOOGLE-PEER","Provider Family":"ipswat.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"437","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as GOOGLE-PEER (ipswat.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS397881","ASN Number":"397881","Network Name":"STINGERS - Stingers Inc.","Aliases":"Stingers Inc.; STINGERS","Provider Family":"ipswat.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"37","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as STINGERS (ipswat.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS398638","ASN Number":"398638","Network Name":"JELLYDIGITAL - Jelly Digital, LLC.","Aliases":"Jelly Digital, LLC.; JELLYDIGITAL","Provider Family":"jellydigital.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"438","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as JELLYDIGITAL (jellydigital.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS398741","ASN Number":"398741","Network Name":"AS-VERTEXLINK-01 - VertexLink Inc","Aliases":"VertexLink Inc; AS-VERTEXLINK-01","Provider Family":"62yun.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"439","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AS-VERTEXLINK-01 (62yun.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS399073","ASN Number":"399073","Network Name":"TBB-ASN - BUNNY TECHNOLOGY LLC","Aliases":"BUNNY TECHNOLOGY LLC; TBB-ASN","Provider Family":"bunnycommunications.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"44","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as TBB-ASN (bunnycommunications.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS399471","ASN Number":"399471","Network Name":"AS-DESEQUITY - Des Equity LLC","Aliases":"Des Equity LLC; CUSTOMER","Provider Family":"serverion.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2026-08-01","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"440","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CUSTOMER (serverion.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS399979","ASN Number":"399979","Network Name":"AS-493NETWORKING - 49.3 Networking LLC","Aliases":"AS-493NETWORKING; 493networking.cc; 49.3 Networking LLC","Provider Family":"AS-493NETWORKING","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Bulletproof / high-risk hosting family","Category":"Source-confirmed BPH (active)","Evidence Level":"High","FP Risk":"Low","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"87","Login / Identity Evidence":"No","Actor / Campaign":"bulletproof hosting; cybercriminal infrastructure","Last Evidence":"2026-09-29","Source IDs":"S01, S02, X071, N01, S03","Evidence Summary":"Spamhaus publicly identified AS399979/49.3 Networking as a bulletproof host and described the operator as using a Delaware shell company. The ASN remains in the live ASN-DROP feed. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AS-493NETWORKING (493networking.cc).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. High: explicit BPH attribution by Spamhaus plus current ASN-DROP inclusion; the ASN announces a very small footprint, reducing carrier-scale collateral risk. Active and announcing routes as 49.3 Networking LLC on 2026-09-15; present in current Spamhaus ASN-DROP.","Current Community Feed Count":"2","Current Listed IPs":"12","IPsum IPs":"8","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"12","Talos 2024 IPs":"0","Multi-list IPs":"8","Listed-IP Country Mix":"DE:12"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS400018","ASN Number":"400018","Network Name":"CLOUD - Africa cloud limited","Aliases":"Africa cloud limited; CLOUD","Provider Family":"seacom.cc","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"441","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CLOUD (seacom.cc).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS400171","ASN Number":"400171","Network Name":"AS-AINFO - Alpha InfoLab Inc","Aliases":"alphainfolab.com; AS-AINFO","Provider Family":"alphainfolab.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2024-12-19","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"442","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AS-AINFO (alphainfolab.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS400177","ASN Number":"400177","Network Name":"RC - rootcloud LLC","Aliases":"rootcloud LLC; RC","Provider Family":"ipswat.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"443","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as RC (ipswat.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS400328","ASN Number":"400328","Network Name":"INTELLIGENCE - Intelligence Hosting LLC","Aliases":"Intelligence Hosting LLC; INTELLIGENCE","Provider Family":"pfcloud.io","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"444","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as INTELLIGENCE (pfcloud.io).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS400377","ASN Number":"400377","Network Name":"AS-DC - Des Equity LLC","Aliases":"serverion.com; CUSTOMER","Provider Family":"serverion.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2025-12-08","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"445","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CUSTOMER (serverion.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS400506","ASN Number":"400506","Network Name":"BAIAS - Black Apple","Aliases":"Black Apple; BAIAS","Provider Family":"blackappleus.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"128","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BAIAS (blackappleus.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"US:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS400522","ASN Number":"400522","Network Name":"ROOTCLOUD - rootcloud LLC","Aliases":"rootcloud LLC; ROOTCLOUD","Provider Family":"ipswat.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"446","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ROOTCLOUD (ipswat.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS400641","ASN Number":"400641","Network Name":"IPV4HOLDINGS - IPv4 Holdings LLC","Aliases":"IPv4 Holdings LLC; IPV4HOLDINGS","Provider Family":"ipv4holdings.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2026-07-29","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"447","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as IPV4HOLDINGS (ipv4holdings.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS400992","ASN Number":"400992","Network Name":"ZHOUYISAT-COMMUNICATIONS - ZhouyiSat Communications","Aliases":"ZhouyiSat Communications; ZHOUYISAT-COMMUNICATIONS","Provider Family":"62yun.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"40","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ZHOUYISAT-COMMUNICATIONS (62yun.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"17","IPsum IPs":"12","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"4","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"US:10, ES:5, DE:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS401109","ASN Number":"401109","Network Name":"ZHONGGUANCUN-CO - Zhongguancun LLC","Aliases":"Zhongguancun LLC; ZHONGGUANCUN-CO","Provider Family":"zhongguancun.asia","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"reserved","Route Status":"Not currently originating","Route Last Seen":"2025-11-12","Network Type":"Mixed / not independently classified","Category":"Former ASN-DROP; non-originating lifecycle review","Evidence Level":"Historical / lifecycle","FP Risk":"Very High","Recommended Use":"Disabled by default. Retain history and review current assignment, origin, and exact indicators before any enforcement.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"448","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-09","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Present in the 2026-10-02 ASN-DROP snapshot and absent from the 2026-10-07 snapshot; delisting does not establish benignness.","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current RIR and routing state require lifecycle review. RIR delegation file lists the ASN as reserved and RDAP returns no object (2026-10-09). Not routed since the date above. Held for lifecycle review rather than removed, because the reserved status is new this week.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS401110","ASN Number":"401110","Network Name":"AS-SOVYCLOUD - Sovy Cloud Services","Aliases":"sovy.cloud; AS-SOVYCLOUD","Provider Family":"sovy.cloud","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"reserved","Route Status":"Not currently originating","Route Last Seen":"2025-02-14","Network Type":"Hosting / VPS / proxy","Category":"Former ASN-DROP; non-originating lifecycle review","Evidence Level":"Historical / lifecycle","FP Risk":"Very High","Recommended Use":"Disabled by default. Retain history and review current assignment, origin, and exact indicators before any enforcement.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"449","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-09","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Present in the 2026-10-02 ASN-DROP snapshot and absent from the 2026-10-07 snapshot; delisting does not establish benignness.","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current RIR and routing state require lifecycle review. RIR delegation file lists the ASN as reserved and RDAP returns no object (2026-10-09). Not routed since the date above. Held for lifecycle review rather than removed, because the reserved status is new this week.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS401116","ASN Number":"401116","Network Name":"NYBULA - Nybula LLC","Aliases":"Nybula LLC; NYBULA","Provider Family":"nybula.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"reserved","Route Status":"Not currently originating","Route Last Seen":"2025-11-12","Network Type":"Mixed / not independently classified","Category":"Former ASN-DROP; non-originating lifecycle review","Evidence Level":"Historical / lifecycle","FP Risk":"Very High","Recommended Use":"Disabled by default. Retain history and review current assignment, origin, and exact indicators before any enforcement.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"450","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-09","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Present in the 2026-10-02 ASN-DROP snapshot and absent from the 2026-10-07 snapshot; delisting does not establish benignness.","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current RIR and routing state require lifecycle review. RIR delegation file lists the ASN as reserved and RDAP returns no object (2026-10-09). Not routed since the date above. Held for lifecycle review rather than removed, because the reserved status is new this week.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS401120","ASN Number":"401120","Network Name":"CHEAPY-HOST - cheapy.host LLC","Aliases":"cheapy.host LLC; CHEAPY-HOST","Provider Family":"cheapy.host","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"reserved","Route Status":"Not currently originating","Route Last Seen":"2025-11-12","Network Type":"Hosting / VPS / proxy","Category":"Former ASN-DROP; non-originating lifecycle review","Evidence Level":"Historical / lifecycle","FP Risk":"Very High","Recommended Use":"Disabled by default. Retain history and review current assignment, origin, and exact indicators before any enforcement.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"451","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-09","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Present in the 2026-10-02 ASN-DROP snapshot and absent from the 2026-10-07 snapshot; delisting does not establish benignness.","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current RIR and routing state require lifecycle review. RIR delegation file lists the ASN as reserved and RDAP returns no object (2026-10-09). Not routed since the date above. Held for lifecycle review rather than removed, because the reserved status is new this week.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS401626","ASN Number":"401626","Network Name":"NETIFACE-TORONTO - Netiface America, Inc.","Aliases":"Netiface America, Inc.; NETIFACE-TORONTO","Provider Family":"netiface.co.uk","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"35","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NETIFACE-TORONTO (netiface.co.uk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"108","IPsum IPs":"70","IPsum Score >=3":"3","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"107","Talos 2024 IPs":"0","Multi-list IPs":"69","Listed-IP Country Mix":"DE:108"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS401696","ASN Number":"401696","Network Name":"COGNETCLOUD - cognetcloud INC","Aliases":"cognetcloud INC; COGNETCLOUD","Provider Family":"cognetcloud.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"61","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as COGNETCLOUD (cognetcloud.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"57","IPsum IPs":"34","IPsum Score >=3":"7","IPsum Score >=5":"5","Open-Proxy IPs":"8","Data-Shield IPs":"35","Talos 2024 IPs":"0","Multi-list IPs":"20","Listed-IP Country Mix":"HK:55, US:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS401701","ASN Number":"401701","Network Name":"COGNETCLOUD-2 - cognetcloud INC","Aliases":"cognetcloud INC; COGNETCLOUD-2","Provider Family":"cognetcloud.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"36","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as COGNETCLOUD-2 (cognetcloud.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"48","IPsum IPs":"21","IPsum Score >=3":"4","IPsum Score >=5":"2","Open-Proxy IPs":"19","Data-Shield IPs":"19","Talos 2024 IPs":"0","Multi-list IPs":"11","Listed-IP Country Mix":"HK:48"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS402075","ASN Number":"402075","Network Name":"PEEKABO - Peekabo Networks","Aliases":"Peekabo Networks; PEEKABO","Provider Family":"securecommsgroup.xyz","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"39","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as PEEKABO (securecommsgroup.xyz).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS402253","ASN Number":"402253","Network Name":"SKN-NETWORK-1 - SKN Subnet & Telecom Ltd","Aliases":"SKN Subnet & Telecom Ltd; SKN-NETWORK-1","Provider Family":"skntelecom.com","RIR Country Code":"KN","Country Name":"St. Kitts & Nevis","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"ISP / network operator","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"113","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SKN-NETWORK-1 (skntelecom.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"2","Current Listed IPs":"57","IPsum IPs":"34","IPsum Score >=3":"10","IPsum Score >=5":"3","Open-Proxy IPs":"0","Data-Shield IPs":"52","Talos 2024 IPs":"0","Multi-list IPs":"29","Listed-IP Country Mix":"US:52, CH:5"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS402647","ASN Number":"402647","Network Name":"NETRONEX - Netronex","Aliases":"ipswat.com; NETRONEX_SOLUTIONS","Provider Family":"ipswat.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"452","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NETRONEX_SOLUTIONS (ipswat.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS403005","ASN Number":"403005","Network Name":"BLATANTHOST - blatant.host","Aliases":"BLATANTHOST","Provider Family":"blatant.host","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate identity, device, session, event-country, and post-authentication activity; review dependencies before deny actions.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"47","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S03, N01","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as BLATANTHOST (blatant.host). Current routing and RIR registration were independently refreshed.","Analyst Notes":"Current feed membership is a high-confidence network-risk signal, not proof that every address, tenant, or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS8100","ASN Number":"8100","Network Name":"SPLICE-AS-AP - Splice Internet Pty Ltd","Aliases":"","Provider Family":"SPLICE-AS-AP","RIR Country Code":"AU","Country Name":"Australia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira ransomware targeting SonicWall SSL VPN","Last Evidence":"2025-09-22","Source IDs":"N06, N01","Evidence Summary":"Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS8100 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch ended 2026-03-21: 1 campaign (N06), newest report 2025-09-22. Stepped down T2 to T4 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS9465","ASN Number":"9465","Network Name":"AGOTOZPTELTD-AS-AP - AGOTOZ PTE. LTD.","Aliases":"AGOTOZ PTE. LTD.","Provider Family":"agotoz.com","RIR Country Code":"SG","Country Name":"Singapore","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"26.56","ipapi Rank":"609","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #609 with 26.56% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"2","Current Listed IPs":"256","IPsum IPs":"256","IPsum Score >=3":"57","IPsum Score >=5":"34","Open-Proxy IPs":"0","Data-Shield IPs":"66","Talos 2024 IPs":"0","Multi-list IPs":"66","Listed-IP Country Mix":"HK:256"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS11878","ASN Number":"11878","Network Name":"TZULO - tzulo, inc.","Aliases":"","Provider Family":"tzulo","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch","Evidence Level":"Medium-High","FP Risk":"High","Recommended Use":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"UNC6671 multi-brand vishing, AiTM, and SaaS extortion","Last Evidence":"2026-08-06","Source IDs":"N17, N01","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS11878 across UNC6671 multi-brand vishing, AiTM, and SaaS extortion. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch: 1 campaign (N17). T3 until 2027-02-02. Moved T2 to T3 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"149","IPsum IPs":"121","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"7","Data-Shield IPs":"27","Talos 2024 IPs":"0","Multi-list IPs":"6","Listed-IP Country Mix":"US:137, CA:5, CN:3, GB:2, FR:1, VE:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS14315","ASN Number":"14315","Network Name":"1GSERVERS - 1GSERVERS, LLC","Aliases":"","Provider Family":"1GSERVERS","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira ransomware targeting SonicWall SSL VPN","Last Evidence":"2025-09-22","Source IDs":"N06, N01","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS14315 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch ended 2026-03-21: 1 campaign (N06), newest report 2025-09-22. Stepped down T2 to T4 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"6","IPsum IPs":"2","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"4","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"US:6"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS14956","ASN Number":"14956","Network Name":"ROUTERHOSTING - RouterHosting LLC","Aliases":"Cloudzy; RouterHosting; Webair Internet Development Inc","Provider Family":"","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Commercial VPS/cloud hosting","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-09","Source IDs":"S01, S02, S05, X016, X017, X018, N01","Evidence Summary":"Listed in the 2026-10-09 Spamhaus ASN-DROP snapshot (ROUTERHOSTING, cloudzy.com). Halcyon reported substantial Cloudzy infrastructure used by ransomware and nation-state C2 and alleged a permissive operating model; Cloudzy disputed those conclusions. JUMPSEC subsequently mapped multiple 2026 DPRK BlueNoroff campaign domains to AS14956. Repeated malicious use is strong; knowing complicity remains disputed.","Analyst Notes":"A direct end-user sign-in from this VPS network is high-value context, but blanket blocking can affect legitimate Cloudzy tenants and should respect documented exceptions. Moved T2 to T1 on ASN-DROP listing, which is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"229","IPsum IPs":"83","IPsum Score >=3":"17","IPsum Score >=5":"4","Open-Proxy IPs":"24","Data-Shield IPs":"180","Talos 2024 IPs":"0","Multi-list IPs":"58","Listed-IP Country Mix":"US:174, NL:20, SG:16, CH:8, DE:6, AU:4, AE:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS20052","ASN Number":"20052","Network Name":"ARBOR - Arbor Networks, Inc.","Aliases":"Arbor Networks, Inc.","Provider Family":"netscout.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"89.26","ipapi Rank":"470","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #470 with 89.26% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"2","Current Listed IPs":"116","IPsum IPs":"22","IPsum Score >=3":"12","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"115","Talos 2024 IPs":"0","Multi-list IPs":"21","Listed-IP Country Mix":"US:116"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS20292","ASN Number":"20292","Network Name":"AS-MRQDNTWRKS miriquidi networks GmbH","Aliases":"miriquidi networks GmbH","Provider Family":"miriquidi-networks.com","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"50","ipapi Rank":"516","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #516 with 50% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS21249","ASN Number":"21249","Network Name":"RUTIL-BG-AS Rutil Ltd.","Aliases":"","Provider Family":"RUTIL-BG-AS Rutil Ltd.","RIR Country Code":"BG","Country Name":"Bulgaria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira ransomware targeting SonicWall SSL VPN","Last Evidence":"2025-09-22","Source IDs":"N06, N01","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS21249 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch ended 2026-03-21: 1 campaign (N06), newest report 2025-09-22. Stepped down T2 to T4 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"2","Current Listed IPs":"5","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"3","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"BG:5"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS23470","ASN Number":"23470","Network Name":"RELIABLESITE - ReliableSite.Net LLC","Aliases":"","Provider Family":"RELIABLESITE","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira ransomware targeting SonicWall SSL VPN","Last Evidence":"2025-09-22","Source IDs":"N06, N01","Evidence Summary":"Published reporting includes 3 time-bounded indicators attributed to or currently mapped to AS23470 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch ended 2026-03-21: 1 campaign (N06), newest report 2025-09-22. Stepped down T2 to T4 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"75","IPsum IPs":"39","IPsum Score >=3":"4","IPsum Score >=5":"0","Open-Proxy IPs":"7","Data-Shield IPs":"45","Talos 2024 IPs":"0","Multi-list IPs":"16","Listed-IP Country Mix":"US:74, NL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS25369","ASN Number":"25369","Network Name":"BANDWIDTH-AS Hydra Communications Ltd","Aliases":"","Provider Family":"Hydra Communications","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch","Evidence Level":"Medium-High","FP Risk":"High","Recommended Use":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"UNC6671 multi-brand vishing, AiTM, and SaaS extortion","Last Evidence":"2026-08-06","Source IDs":"N17, N01","Evidence Summary":"Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS25369 across UNC6671 multi-brand vishing, AiTM, and SaaS extortion. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch: 1 campaign (N17). T3 until 2027-02-02. Moved T2 to T3 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"2650","IPsum IPs":"2598","IPsum Score >=3":"1462","IPsum Score >=5":"384","Open-Proxy IPs":"4","Data-Shield IPs":"2215","Talos 2024 IPs":"1","Multi-list IPs":"2168","Listed-IP Country Mix":"GB:1659, NL:653, DE:322, FR:14, CH:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS29802","ASN Number":"29802","Network Name":"HVC-AS - HIVELOCITY, Inc.","Aliases":"","Provider Family":"HVC-AS","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch","Evidence Level":"Medium-High","FP Risk":"High","Recommended Use":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira and Fog ransomware via SonicWall SSL VPN; Akira ransomware targeting SonicWall SSL VPN","Last Evidence":"2026-04-01","Source IDs":"N07, N06, N10, N01","Evidence Summary":"Published reporting includes 4 time-bounded indicators attributed to or currently mapped to AS29802 across Akira and Fog ransomware via SonicWall SSL VPN; Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant. eSentire saw pre-takedown Tycoon 2FA Microsoft 365 login attempts from AS29802 (2026-04-01).","Analyst Notes":"Campaign watch: 2 campaigns (N06, N10). T2 until 2026-09-28. T3 until 2027-03-27. Moved T2 to T3 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"122","IPsum IPs":"80","IPsum Score >=3":"3","IPsum Score >=5":"1","Open-Proxy IPs":"22","Data-Shield IPs":"33","Talos 2024 IPs":"0","Multi-list IPs":"13","Listed-IP Country Mix":"US:92, NL:10, SG:6, ES:4, GB:3, CA:2, DE:2, JP:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS30633","ASN Number":"30633","Network Name":"LEASEWEB-USA-WDC - Leaseweb USA, Inc.","Aliases":"","Provider Family":"LEASEWEB-USA-WDC","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira ransomware targeting SonicWall SSL VPN","Last Evidence":"2025-09-22","Source IDs":"N06, N01","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS30633 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch ended 2026-03-21: 1 campaign (N06), newest report 2025-09-22. Stepped down T2 to T4 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"93","IPsum IPs":"9","IPsum Score >=3":"2","IPsum Score >=5":"0","Open-Proxy IPs":"84","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"3","Listed-IP Country Mix":"US:93"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS32613","ASN Number":"32613","Network Name":"IWEB-AS - Leaseweb Canada Inc.","Aliases":"","Provider Family":"IWEB-AS","RIR Country Code":"CA","Country Name":"Canada","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira and Fog ransomware via SonicWall SSL VPN","Last Evidence":"2024-10-24","Source IDs":"N07, N01","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS32613 across Akira and Fog ransomware via SonicWall SSL VPN. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch ended 2025-04-22: 1 campaign (N07), newest report 2024-10-24. Stepped down T2 to T4 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"9","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"2","Data-Shield IPs":"5","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"CA:9"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS34254","ASN Number":"34254","Network Name":"HORNET-AS HOR.NET Polska Sp.z o.o.","Aliases":"HOR.NET Polska Sp.z o.o.","Provider Family":"hornet.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"42.44","ipapi Rank":"536","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #536 with 42.44% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"PL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS34939","ASN Number":"34939","Network Name":"nextdns NextDNS, Inc.","Aliases":"NextDNS, Inc.","Provider Family":"nextdns.io","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"31.47","ipapi Rank":"578","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #578 with 31.47% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS36352","ASN Number":"36352","Network Name":"AS-COLOCROSSING - HostPapa","Aliases":"","Provider Family":"AS-COLOCROSSING","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira ransomware targeting SonicWall SSL VPN","Last Evidence":"2025-09-22","Source IDs":"N06, N01","Evidence Summary":"Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS36352 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch ended 2026-03-21: 1 campaign (N06), newest report 2025-09-22. Stepped down T2 to T4 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS39287","ASN Number":"39287","Network Name":"materialism Materialism s.r.l.","Aliases":"Njalla","Provider Family":"Njalla","RIR Country Code":"RO","Country Name":"Romania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Related provider or broad shared-service context","Evidence Level":"Context","FP Risk":"Medium","Recommended Use":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N18, N21, N01","Evidence Summary":"Active related network for Njalla. No direct provider-level malicious designation was established; retain as enabled T2 monitoring context and require device, session, event-country, or post-authentication corroboration.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"2","Current Listed IPs":"14","IPsum IPs":"10","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"5","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"SE:11, FI:2, DK:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS43641","ASN Number":"43641","Network Name":"Sollutium-NL SOLLUTIUM EU Sp z.o.o.","Aliases":"","Provider Family":"Sollutium-NL SOLLUTIUM EU Sp z.o.o.","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira and Fog ransomware via SonicWall SSL VPN","Last Evidence":"2024-10-24","Source IDs":"N07, N01","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS43641 across Akira and Fog ransomware via SonicWall SSL VPN. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch ended 2025-04-22: 1 campaign (N07), newest report 2024-10-24. Stepped down T2 to T4 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"37","IPsum IPs":"27","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"7","Data-Shield IPs":"15","Talos 2024 IPs":"0","Multi-list IPs":"12","Listed-IP Country Mix":"NL:37"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS47516","ASN Number":"47516","Network Name":"DEHOST DEHOST INTERNET VE BILISIM TEKNOLOJILERI SANAYI TICARET LIMITED SIRKETI","Aliases":"DEHOST INTERNET VE BILISIM TEKNOLOJILERI","Provider Family":"dehost.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"56.43","ipapi Rank":"496","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #496 with 56.43% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS48282","ASN Number":"48282","Network Name":"VDSINA-AS Hosting technology LTD","Aliases":"VDSina; UAB Rakrejus (Kaunas); Hosting technology LTD (Russia)","Provider Family":"","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"VPS/VDS hosting","Category":"Legacy hosting/VPS watchlist","Evidence Level":"Strong","FP Risk":"Medium","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2024-08-12","Source IDs":"S05, X001, X002, N01","Evidence Summary":"Rapid7 explicitly attributed multiple command-and-control addresses in a 2024 social-engineering/malware campaign to low-cost VDSINA infrastructure on AS48282 and recommended blocking low-cost VPS/VDS networks where unnecessary. Silent Push separately documented phishing and malware infrastructure on this ASN. This establishes repeated malicious use, not provider complicity.","Analyst Notes":"A user sign-in from low-cost VDS hosting is unusual and the ASN has explicit C2 history, but legitimate tenants exist; do not label the provider itself malicious without stronger evidence.","Current Community Feed Count":"3","Current Listed IPs":"55","IPsum IPs":"43","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"12","Data-Shield IPs":"24","Talos 2024 IPs":"0","Multi-list IPs":"24","Listed-IP Country Mix":"RU:55"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS48721","ASN Number":"48721","Network Name":"FLYSERVERS-ENDCLIENTS Flyservers S.A.","Aliases":"Flyservers; Flyservers S.A.","Provider Family":"Flyservers","RIR Country Code":"PA","Country Name":"Panama","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Bulletproof / high-risk hosting family","Category":"Published BPH attribution, older evidence (active)","Evidence Level":"Medium","FP Risk":"Medium-High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"adversary command-and-control hosting","Last Evidence":"2022-12-15","Source IDs":"X057, N01","Evidence Summary":"Recorded Future's 2022 Adversary Infrastructure Report explicitly listed Flyservers S.A. among known BPH providers and mapped it to AS48721 in its ASN table.","Analyst Notes":"Medium: provider-level BPH wording is explicit, but the public evidence is older and should be refreshed with current IP/campaign signals. Active and announcing routes as Flyservers S.A. on 2026-09-15. Watch/step-up tier pending fresh corroboration.","Current Community Feed Count":"2","Current Listed IPs":"12","IPsum IPs":"11","IPsum Score >=3":"6","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"10","Talos 2024 IPs":"0","Multi-list IPs":"9","Listed-IP Country Mix":"LT:12"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS50867","ASN Number":"50867","Network Name":"ORG-LVA15-AS HOSTKEY B.V.","Aliases":"","Provider Family":"ORG-LVA15-AS HOSTKEY B.V.","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Console Chaos FortiGate management-interface exploitation","Last Evidence":"2025-01-10","Source IDs":"N09, N01","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS50867 across Console Chaos FortiGate management-interface exploitation. This does not implicate the provider or every tenant.","Analyst Notes":"Stepped down T2 to T4 on 2026-10-07: N09 reports FortiGate management-interface exploitation, which is not identity or VPN-authentication abuse, so it gives no campaign-watch basis. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"17","IPsum IPs":"14","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"2","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"RU:17"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS51852","ASN Number":"51852","Network Name":"PLI-AS Private Layer INC","Aliases":"","Provider Family":"Private Layer","RIR Country Code":"PA","Country Name":"Panama","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Published campaign infrastructure in shared hosting or VPN space","Evidence Level":"Medium-High","FP Risk":"Medium","Recommended Use":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"UNC6671 multi-brand vishing, AiTM, and SaaS extortion","Last Evidence":"2026-08-06","Source IDs":"N17, N01","Evidence Summary":"Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS51852 across UNC6671 multi-brand vishing, AiTM, and SaaS extortion. This does not implicate the provider or every tenant.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"2","Current Listed IPs":"99","IPsum IPs":"80","IPsum Score >=3":"4","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"34","Talos 2024 IPs":"1","Multi-list IPs":"15","Listed-IP Country Mix":"CH:89, GB:9, NL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS53667","ASN Number":"53667","Network Name":"PONYNET - FranTech Solutions","Aliases":"FranTech Solutions; BuyVM; PONYNET; FranTechSolutions","Provider Family":"FranTech / BuyVM","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Low-cost VPS / VPN hosting","Category":"Campaign watch","Evidence Level":"High","FP Risk":"High","Recommended Use":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.17","ipapi Rank":"972","Login / Identity Evidence":"Yes","Actor / Campaign":"LSHIY password spray","Last Evidence":"2026-07-15","Source IDs":"S02, S03, S05, X008, N01","Evidence Summary":"Huntress reported a 2026 Microsoft 365 and Azure CLI password-spray wave moving into AS53667 IPv6 space. Huntress observed a 2026 Microsoft 365/Azure CLI password-spray wave move to AS53667 IPv6 space, with 87% target overlap from the preceding provider and prior password-spray history. This is direct identity-attack evidence but does not establish provider complicity. ipapi.is ranks this hosting ASN #963 with 12.11% observed abuse concentration (High).","Analyst Notes":"Campaign watch: 1 campaign (X008). T3 until 2027-01-11. Moved T2 to T3 on 2026-10-07 when the ladder was applied retroactively. Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious. Direct recent password-spray origin is highly relevant to Entra ID monitoring; allowlist only documented administrative or vendor use.","Current Community Feed Count":"3","Current Listed IPs":"237","IPsum IPs":"209","IPsum Score >=3":"21","IPsum Score >=5":"7","Open-Proxy IPs":"11","Data-Shield IPs":"145","Talos 2024 IPs":"12","Multi-list IPs":"128","Listed-IP Country Mix":"US:141, LU:91, CH:5"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS55286","ASN Number":"55286","Network Name":"SERVER-MANIA - B2 Net Solutions Inc.","Aliases":"","Provider Family":"ServerMania / B2 Net Solutions","RIR Country Code":"CA","Country Name":"Canada","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared VPS / dedicated hosting","Category":"Campaign watch ended; retained for history","Evidence Level":"High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Proofpoint 2022 cloud credential attacks","Last Evidence":"2022-03-03","Source IDs":"S04, S06, N01","Evidence Summary":"Eight Proofpoint cloud login-source IOCs historically originated from AS55286 during the campaign window. Use as a step-up signal because ServerMania is shared hosting.","Analyst Notes":"Campaign watch ended 2022-08-30: 1 campaign (S04), newest report 2022-03-03. Stepped down T2 to T4 on 2026-10-07 when the ladder was applied retroactively.","Current Community Feed Count":"3","Current Listed IPs":"752","IPsum IPs":"61","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"683","Data-Shield IPs":"7","Talos 2024 IPs":"3","Multi-list IPs":"2","Listed-IP Country Mix":"US:677, CA:47, FR:20, ES:4, GB:3, NL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS56153","ASN Number":"56153","Network Name":"LUUTRUSO-AS-VN - Digital Storage Company Limited","Aliases":"Digital Storage Company Limited","Provider Family":"123host.vn","RIR Country Code":"VN","Country Name":"Vietnam","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"73.05","ipapi Rank":"476","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #476 with 73.05% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"3","Current Listed IPs":"5","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"VN:5"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS58061","ASN Number":"58061","Network Name":"SCALAXY-AS Scalaxy B.V.","Aliases":"","Provider Family":"SCALAXY-AS Scalaxy B.V.","RIR Country Code":"LV","Country Name":"Latvia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Conditional fast-flux and shared-hosting context","Evidence Level":"Medium","FP Risk":"Medium","Recommended Use":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"Silent Push fast-flux analytic","Last Evidence":"2026-09-15","Source IDs":"N01, N38","Evidence Summary":"Silent Push included AS58061 in a conditional multi-ASN fast-flux DNS analytic. The source explicitly warns that not every rotating ASN is bulletproof; preserve T2 monitoring but require the full DNS-diversity or identity/behavior context.","Analyst Notes":"Community-feed counts are informational and do not determine this tier. Analytic inclusion is infrastructure context, not proof of provider complicity or a basis for ASN-only blocking.","Current Community Feed Count":"3","Current Listed IPs":"44","IPsum IPs":"30","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"10","Data-Shield IPs":"8","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"NL:32, FI:5, KZ:2, US:2, AR:1, DE:1, TR:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS59711","ASN Number":"59711","Network Name":"HZ-EU-AS HZ Hosting Ltd","Aliases":"","Provider Family":"HZ-EU-AS HZ Hosting Ltd","RIR Country Code":"BG","Country Name":"Bulgaria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch","Evidence Level":"Medium-High","FP Risk":"High","Recommended Use":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira and Fog ransomware via SonicWall SSL VPN","Last Evidence":"2026-04-06","Source IDs":"N07, N59, N01","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS59711 across Akira and Fog ransomware via SonicWall SSL VPN. This does not implicate the provider or every tenant. Microsoft listed 89.150.45.0 (HZ Hosting), originated by AS59711, as threat actor infrastructure observed with sign-in on 2026-04-06.","Analyst Notes":"Campaign watch: 3 campaigns across the HZ Hosting family (N07, N06, N59). T2 until 2026-10-03. T3 until 2027-04-01. Moved T2 to T3 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"19","IPsum IPs":"12","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"5","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"FR:4, NL:4, PL:4, SE:3, EE:2, AE:1, DE:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS60117","ASN Number":"60117","Network Name":"HS Host Sailor Ltd","Aliases":"HostSailor; Host Sailor Ltd","Provider Family":"HostSailor","RIR Country Code":"AE","Country Name":"United Arab Emirates","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Bulletproof / high-risk hosting family","Category":"Published BPH attribution, older evidence (active)","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"adversary command-and-control hosting","Last Evidence":"2022-12-15","Source IDs":"X057, N01","Evidence Summary":"Recorded Future's 2022 report described Host Sailor Ltd as a BPH provider observed in adversary infrastructure and mapped it to AS60117.","Analyst Notes":"Medium: explicit provider-level wording but stale public evidence; current posture should be refreshed before punitive action. Active and announcing routes as Host Sailor Ltd on 2026-09-15. Watch tier only without fresher corroboration.","Current Community Feed Count":"2","Current Listed IPs":"24","IPsum IPs":"23","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"NL:20, RO:4"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS60602","ASN Number":"60602","Network Name":"INOVARE-AS Inovare-Prim SRL","Aliases":"","Provider Family":"INOVARE-AS Inovare-Prim SRL","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira ransomware targeting SonicWall SSL VPN","Last Evidence":"2025-09-22","Source IDs":"N06, N01","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS60602 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch ended 2026-03-21: 1 campaign (N06), newest report 2025-09-22. Stepped down T2 to T4 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"MD:1, RO:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS60647","ASN Number":"60647","Network Name":"MERT-TURKOGLU-DATAHOST-INTERNET-VE-BILISIM-TEKNOLOJILERI MERT TURKOGLU trading as DATAHOST INTERNET VE BILISIM TEKNOLOJILERI","Aliases":"MERT TURKOGLU trading as DATAHOST INTERN","Provider Family":"datahost.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S02, S03, N01","Evidence Summary":"This ASN appeared in the Very High band at rank #472 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS60890","ASN Number":"60890","Network Name":"CENTRALNIC-ANYCAST-B CentralNic Ltd","Aliases":"CentralNic Ltd","Provider Family":"centralnic.com","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"37.5","ipapi Rank":"546","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #546 with 37.5% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS61125","ASN Number":"61125","Network Name":"SABOTAGE SABOTAGE LLC","Aliases":"SABOTAGE LLC","Provider Family":"sabotage.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"24.61","ipapi Rank":"628","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #628 with 24.61% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"2","Current Listed IPs":"26","IPsum IPs":"26","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"25","Talos 2024 IPs":"0","Multi-list IPs":"25","Listed-IP Country Mix":"SC:26"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS62005","ASN Number":"62005","Network Name":"BV-EU-AS BlueVPS OU","Aliases":"","Provider Family":"BlueVPS","RIR Country Code":"EE","Country Name":"Estonia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira ransomware targeting SonicWall SSL VPN; MuddyWater / BugSleep infrastructure cluster","Last Evidence":"2025-09-22","Source IDs":"N06, N08, N01","Evidence Summary":"Published reporting includes 5 time-bounded indicators attributed to or currently mapped to AS62005 across Akira ransomware targeting SonicWall SSL VPN; MuddyWater / BugSleep infrastructure cluster. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch ended 2026-03-21: 1 campaign (N06), newest report 2025-09-22. Stepped down T2 to T4 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"39","IPsum IPs":"25","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"17","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"EE:12, NL:11, ES:4, PL:4, US:3, AE:1, BG:1, DE:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS62904","ASN Number":"62904","Network Name":"AS62904 - Eonix Corporation","Aliases":"","Provider Family":"AS62904","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira ransomware targeting SonicWall SSL VPN","Last Evidence":"2025-09-22","Source IDs":"N06, N01","Evidence Summary":"Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS62904 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch ended 2026-03-21: 1 campaign (N06), newest report 2025-09-22. Stepped down T2 to T4 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"59","IPsum IPs":"50","IPsum Score >=3":"20","IPsum Score >=5":"1","Open-Proxy IPs":"6","Data-Shield IPs":"29","Talos 2024 IPs":"0","Multi-list IPs":"26","Listed-IP Country Mix":"US:59"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS63473","ASN Number":"63473","Network Name":"HOSTHATCH - HostHatch, LLC","Aliases":"","Provider Family":"HOSTHATCH","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira ransomware targeting SonicWall SSL VPN","Last Evidence":"2025-09-22","Source IDs":"N06, N01","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS63473 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch ended 2026-03-21: 1 campaign (N06), newest report 2025-09-22. Stepped down T2 to T4 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"41","IPsum IPs":"22","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"9","Data-Shield IPs":"13","Talos 2024 IPs":"0","Multi-list IPs":"3","Listed-IP Country Mix":"SE:8, HK:6, US:6, NL:5, GB:4, AU:3, CH:3, SG:3"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS63734","ASN Number":"63734","Network Name":"GREENCLOUDVPS-AS-VN - 365 Online technology joint stock company","Aliases":"365 Online technology joint stock compan","Provider Family":"greencloudvps.com","RIR Country Code":"VN","Country Name":"Vietnam","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"99.22","ipapi Rank":"464","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #464 with 99.22% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"2","Current Listed IPs":"3","IPsum IPs":"3","IPsum Score >=3":"2","IPsum Score >=5":"1","Open-Proxy IPs":"0","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"3","Listed-IP Country Mix":"VN:3"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS64199","ASN Number":"64199","Network Name":"TCPSHIELD - TCPShield","Aliases":"TCPShield","Provider Family":"tcpshield.com","RIR Country Code":"CA","Country Name":"Canada","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"84.38","ipapi Rank":"472","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #472 with 84.38% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS64236","ASN Number":"64236","Network Name":"UNREAL-SERVERS - UnReal Servers, LLC","Aliases":"","Provider Family":"UNREAL-SERVERS","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira and Fog ransomware via SonicWall SSL VPN; Akira ransomware targeting SonicWall SSL VPN","Last Evidence":"2025-09-22","Source IDs":"N07, N06, N01","Evidence Summary":"Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS64236 across Akira and Fog ransomware via SonicWall SSL VPN; Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch ended 2026-09-17: 2 campaigns (N07, N06), newest report 2025-09-22. Stepped down T2 to T4 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"15","IPsum IPs":"13","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"US:15"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS131199","ASN Number":"131199","Network Name":"NEXEON-AS-AP - Nexeon Technologies, Inc.","Aliases":"","Provider Family":"NEXEON-AS-AP","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira ransomware targeting SonicWall SSL VPN","Last Evidence":"2025-09-22","Source IDs":"N06, N01","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS131199 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch ended 2026-03-21: 1 campaign (N06), newest report 2025-09-22. Stepped down T2 to T4 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS136787","ASN Number":"136787","Network Name":"PACKETHUBSA-AS-AP - PacketHub S.A.","Aliases":"PacketHub S.A.","Provider Family":"PacketHub","RIR Country Code":"PA","Country Name":"Panama","Geography Scope":"Foreign","Provider Legal Country":"Panama","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Commercial VPN / hosting / proxy","Category":"Commercial VPN / anonymizer infrastructure","Evidence Level":"High","FP Risk":"Medium-High","Recommended Use":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"EvilTokens post-compromise Microsoft 365 token replay; NordVPN-associated egress; EvilTokens token replay; exploitation and DDoS observations","Last Evidence":"2026-04-06","Source IDs":"N15, N16, N29, N30, N31, N01","Evidence Summary":"PacketHub S.A. operates global hosting infrastructure associated with NordVPN exit traffic. Published reporting observed PacketHub infrastructure in token replay, exploitation, and DDoS activity. Monitor unexpected employee logins; there is no evidence of provider complicity.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"2","Current Listed IPs":"4","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RS:2, DE:1, US:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS140947","ASN Number":"140947","Network Name":"SNTHOSTINGS-AS-AP - SnTHostings","Aliases":"SnTHostings","Provider Family":"snthostings.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"52.34","ipapi Rank":"505","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #505 with 52.34% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS141039","ASN Number":"141039","Network Name":"PACKETHUBSA-AS-AP - PacketHub S.A.","Aliases":"PacketHub S.A.","Provider Family":"PacketHub","RIR Country Code":"PA","Country Name":"Panama","Geography Scope":"Foreign","Provider Legal Country":"Panama","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Commercial VPN / hosting / proxy","Category":"Commercial VPN / anonymizer infrastructure","Evidence Level":"Medium","FP Risk":"Medium-High","Recommended Use":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"NordVPN-associated egress; EvilTokens token replay; exploitation and DDoS observations","Last Evidence":"2026-09-15","Source IDs":"N15, N16, N29, N30, N31, N01","Evidence Summary":"PacketHub S.A. operates global hosting infrastructure associated with NordVPN exit traffic. Published reporting observed PacketHub infrastructure in token replay, exploitation, and DDoS activity. Monitor unexpected employee logins; there is no evidence of provider complicity.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"1","Current Listed IPs":"2","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"US:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS147049","ASN Number":"147049","Network Name":"PACKETHUBSA-AS-AP - PacketHub S.A.","Aliases":"PacketHub S.A.","Provider Family":"PacketHub","RIR Country Code":"AU","Country Name":"Australia","Geography Scope":"Foreign","Provider Legal Country":"Panama","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Commercial VPN / hosting / proxy","Category":"Commercial VPN / anonymizer infrastructure","Evidence Level":"Medium","FP Risk":"Medium-High","Recommended Use":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"NordVPN-associated egress; EvilTokens token replay; exploitation and DDoS observations","Last Evidence":"2026-09-15","Source IDs":"N15, N16, N29, N30, N31, N01","Evidence Summary":"PacketHub S.A. operates global hosting infrastructure associated with NordVPN exit traffic. Published reporting observed PacketHub infrastructure in token replay, exploitation, and DDoS activity. Monitor unexpected employee logins; there is no evidence of provider complicity.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"CA:1, US:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS149089","ASN Number":"149089","Network Name":"CLOUDFLY-VN - CLOUDFLY CORPORATION","Aliases":"CLOUDFLY CORPORATION","Provider Family":"cloudfly.vn","RIR Country Code":"VN","Country Name":"Vietnam","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"98.58","ipapi Rank":"465","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #465 with 98.58% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"3","Current Listed IPs":"6","IPsum IPs":"5","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"3","Listed-IP Country Mix":"VN:6"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS149440","ASN Number":"149440","Network Name":"EVOXTSDNBHD-AS-AP - Evoxt Sdn. Bhd.","Aliases":"","Provider Family":"EVOXTSDNBHD-AS-AP","RIR Country Code":"MY","Country Name":"Malaysia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Console Chaos FortiGate management-interface exploitation","Last Evidence":"2025-01-10","Source IDs":"N09, N01","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS149440 across Console Chaos FortiGate management-interface exploitation. This does not implicate the provider or every tenant.","Analyst Notes":"Stepped down T2 to T4 on 2026-10-07: N09 reports FortiGate management-interface exploitation, which is not identity or VPN-authentication abuse, so it gives no campaign-watch basis. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"18","IPsum IPs":"10","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"6","Data-Shield IPs":"5","Talos 2024 IPs":"0","Multi-list IPs":"3","Listed-IP Country Mix":"US:5, CA:3, HK:3, MY:3, GB:2, FR:1, JP:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS199330","ASN Number":"199330","Network Name":"CENTRALNIC-ANYCAST-A CentralNic Ltd","Aliases":"CentralNic Ltd","Provider Family":"centralnic.com","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"37.5","ipapi Rank":"547","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #547 with 37.5% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS199724","ASN Number":"199724","Network Name":"TEKNODC TeknoDC Bilisim Teknolojileri A.S.","Aliases":"TeknoDC Bilisim Teknolojileri A.S.","Provider Family":"teknodc.net","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"27.88","ipapi Rank":"597","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #597 with 27.88% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"TR:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS200651","ASN Number":"200651","Network Name":"FlokiNET FlokiNET ehf","Aliases":"","Provider Family":"FlokiNET","RIR Country Code":"IS","Country Name":"Iceland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Source-described bulletproof hosting monolith","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"Bulletproof hosting","Last Evidence":"2026-09-15","Source IDs":"N19, N01","Evidence Summary":"Censys identifies FlokiNET AS200651 as a widely recognized bulletproof-hosting monolith. Use for monitoring and triage, not unconditional blocking of every customer.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"45","IPsum IPs":"38","IPsum Score >=3":"3","IPsum Score >=5":"0","Open-Proxy IPs":"3","Data-Shield IPs":"21","Talos 2024 IPs":"4","Multi-list IPs":"18","Listed-IP Country Mix":"RO:25, DE:10, NL:7, IS:2, FI:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS201303","ASN Number":"201303","Network Name":"CentralNic-Anycast-F CentralNic Ltd","Aliases":"CentralNic Ltd","Provider Family":"centralnic.com","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"36.33","ipapi Rank":"553","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #553 with 36.33% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS201304","ASN Number":"201304","Network Name":"CENTRALNIC-ANYCAST-E CentralNic Ltd","Aliases":"CentralNic Ltd","Provider Family":"centralnic.com","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"36.33","ipapi Rank":"552","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #552 with 36.33% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS201814","ASN Number":"201814","Network Name":"Mevspace MEVSPACE sp. z o.o.","Aliases":"","Provider Family":"MEVSPACE","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Published campaign infrastructure in shared hosting or VPN space","Evidence Level":"Medium-High","FP Risk":"Medium","Recommended Use":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Doko's Panel / ShinyHunters phishing-panel infrastructure; UNC6671 multi-brand vishing, AiTM, and SaaS extortion; UNC6671 phishing infrastructure","Last Evidence":"2026-08-06","Source IDs":"N18, N17, N21, N01","Evidence Summary":"Published reporting includes 4 time-bounded indicators attributed to or currently mapped to AS201814 across Doko's Panel / ShinyHunters phishing-panel infrastructure; UNC6671 multi-brand vishing, AiTM, and SaaS extortion; UNC6671 phishing infrastructure. This does not implicate the provider or every tenant.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"429","IPsum IPs":"428","IPsum Score >=3":"3","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"82","Talos 2024 IPs":"0","Multi-list IPs":"82","Listed-IP Country Mix":"PL:170, GB:119, DE:50, BG:47, NL:43"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS202015","ASN Number":"202015","Network Name":"HZ-US-AS HZ Hosting Ltd","Aliases":"","Provider Family":"HZ-US-AS HZ Hosting Ltd","RIR Country Code":"BG","Country Name":"Bulgaria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch","Evidence Level":"Medium-High","FP Risk":"High","Recommended Use":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira and Fog ransomware via SonicWall SSL VPN; Akira ransomware targeting SonicWall SSL VPN","Last Evidence":"2026-04-06","Source IDs":"N07, N06, N59, N01","Evidence Summary":"Published reporting includes 4 time-bounded indicators attributed to or currently mapped to AS202015 across Akira and Fog ransomware via SonicWall SSL VPN; Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch: 3 campaigns across the HZ Hosting family (N07, N06, N59). T2 until 2026-10-03. T3 until 2027-04-01. Moved T2 to T3 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"1","Current Listed IPs":"83","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"83","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"US:78, FR:5"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS203771","ASN Number":"203771","Network Name":"SERVERVIA SERVERVIA BILISIM YAZILIM VE TELEKOMUNIKASYON HIZMETLERI LIMITED SIRKETI","Aliases":"SERVERVIA BILISIM YAZILIM VE TELEKOMUNIK","Provider Family":"servervia.com","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"24.78","ipapi Rank":"626","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #626 with 24.78% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS203979","ASN Number":"203979","Network Name":"BIZIMBULUT-TR Bizim Bulut Bilgi ve Iletisim Hizmetleri San. ve Tic. A. S.","Aliases":"Bizim Bulut Bilgi ve Iletisim Hizmetleri","Provider Family":"bizimbulut.com","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"99.61","ipapi Rank":"459","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #459 with 99.61% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS204491","ASN Number":"204491","Network Name":"TEKNOSOS TEKNOSOS LLC","Aliases":"TEKNOSOS LLC","Provider Family":"teknosos.com.tr","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.06","ipapi Rank":"871","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #871 with 14.06% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS205733","ASN Number":"205733","Network Name":"AS-HOSTIFOX HOSTIFOX INTERNET VE BILISIM HIZMETLERI TICARET SANAYI LIMITED SIRKETI","Aliases":"HOSTIFOX INTERNET VE BILISIM HIZMETLERI","Provider Family":"hostifox.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"86.52","ipapi Rank":"471","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #471 with 86.52% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS206991","ASN Number":"206991","Network Name":"IXIR Iksir Internet Hizmetleri A.S.","Aliases":"Iksir Internet Hizmetleri A.S.","Provider Family":"ixirhost.com","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"25.17","ipapi Rank":"622","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #622 with 25.17% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"1","Current Listed IPs":"3","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"2","Talos 2024 IPs":"1","Multi-list IPs":"0","Listed-IP Country Mix":"TR:3"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS207137","ASN Number":"207137","Network Name":"PACKETHUBSA PacketHub S.A.","Aliases":"PacketHub S.A.","Provider Family":"PacketHub","RIR Country Code":"PA","Country Name":"Panama","Geography Scope":"Foreign","Provider Legal Country":"Panama","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Commercial VPN / hosting / proxy","Category":"Commercial VPN / anonymizer infrastructure","Evidence Level":"Medium","FP Risk":"Medium-High","Recommended Use":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"NordVPN-associated egress; EvilTokens token replay; exploitation and DDoS observations","Last Evidence":"2026-09-15","Source IDs":"N15, N16, N29, N30, N31, N01","Evidence Summary":"PacketHub S.A. operates global hosting infrastructure associated with NordVPN exit traffic. Published reporting observed PacketHub infrastructure in token replay, exploitation, and DDoS activity. Monitor unexpected employee logins; there is no evidence of provider complicity.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"1","Current Listed IPs":"22","IPsum IPs":"22","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"LV:18, DE:2, IT:1, LU:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS207326","ASN Number":"207326","Network Name":"HostLAB HostLAB Bilisim Teknolojileri A.S.","Aliases":"HostLAB Bilisim Teknolojileri A.S.","Provider Family":"hostlab.com","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"61.91","ipapi Rank":"489","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #489 with 61.91% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"2","Current Listed IPs":"3","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"TR:3"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS209474","ASN Number":"209474","Network Name":"EKIPHOST EKIPHOST BILISIM TEKNOLOJILERI TICARET VE SANAYI LIMITED SIRKETI","Aliases":"EKIPHOST BILISIM TEKNOLOJILERI TICARET V","Provider Family":"ekiphost.com","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"77.99","ipapi Rank":"475","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #475 with 77.99% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS209588","ASN Number":"209588","Network Name":"FLYSERVERS-ASN Flyservers S.A.","Aliases":"Flyservers; Flyservers S.A.","Provider Family":"Flyservers","RIR Country Code":"PA","Country Name":"Panama","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Bulletproof / high-risk hosting family","Category":"Published BPH attribution, older evidence (active)","Evidence Level":"Medium","FP Risk":"Medium-High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"adversary command-and-control hosting","Last Evidence":"2022-12-15","Source IDs":"X057, N01","Evidence Summary":"Recorded Future's 2022 report explicitly identified Flyservers S.A. as a known BPH provider and mapped AS209588 to it in the report's ASN table.","Analyst Notes":"Medium: explicit provider-level classification, tempered by the age of the public report. Active and announcing routes as Flyservers S.A. on 2026-09-15. Watch/step-up tier pending fresh corroboration.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"2","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"GB:1, UA:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS210940","ASN Number":"210940","Network Name":"SEASONCLOUD SEASON CLOUD LTDA","Aliases":"SEASON CLOUD LTDA","Provider Family":"seasoncloud.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"49.02","ipapi Rank":"523","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #523 with 49.02% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS211301","ASN Number":"211301","Network Name":"UNESTY Collin Schneeweiss trading as Unesty Company","Aliases":"Collin Schneeweiss trading as Unesty Com","Provider Family":"unesty.net","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"95.02","ipapi Rank":"469","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #469 with 95.02% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"2","Current Listed IPs":"6","IPsum IPs":"4","IPsum Score >=3":"2","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"4","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"DE:6"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS211859","ASN Number":"211859","Network Name":"OZKULA Ozkula Internet Hizmetleri Tic. LTD. STI.","Aliases":"Ozkula Internet Hizmetleri Tic. LTD. STI","Provider Family":"ozkula.com","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"24.02","ipapi Rank":"634","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #634 with 24.02% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"TR:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS212238","ASN Number":"212238","Network Name":"CDNEXT Datacamp Limited","Aliases":"","Provider Family":"CDNEXT Datacamp Limited","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Commercial VPN / anonymizer infrastructure","Evidence Level":"Medium-High","FP Risk":"Medium","Recommended Use":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"UNK_CondorFiltration post-access VPN pivot; Console Chaos FortiGate management-interface exploitation","Last Evidence":"2026-09-22","Source IDs":"N09, N57, N64, N01","Evidence Summary":"Datacamp (CDN77, DataPacket) hosts commercial VPN and anonymizer services (Netify). Proofpoint's TeamFiltration report shows the actor's post-access VPN pivot from 149.88.104.19, originated by AS212238, in 2026. Arctic Wolf also published one Console Chaos management-interface indicator here.","Analyst Notes":"Held at T2 on 2026-10-07 as commercial VPN and anonymizer egress, the basis the T2 definition names, like PacketHub, rather than on the campaign ladder. Shared with many legitimate VPN users.","Current Community Feed Count":"3","Current Listed IPs":"805","IPsum IPs":"524","IPsum Score >=3":"47","IPsum Score >=5":"0","Open-Proxy IPs":"72","Data-Shield IPs":"435","Talos 2024 IPs":"6","Multi-list IPs":"232","Listed-IP Country Mix":"US:449, DE:76, GB:25, ES:21, NL:19, AT:18, SG:18, CA:16"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS212835","ASN Number":"212835","Network Name":"SHESTERNIN-AS Shesternin Vladimir Anatolievich","Aliases":"Shesternin Vladimir Anatolievich","Provider Family":"phost.kz","RIR Country Code":"KZ","Country Name":"Kazakhstan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"23.83","ipapi Rank":"638","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #638 with 23.83% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"2","Current Listed IPs":"27","IPsum IPs":"26","IPsum Score >=3":"5","IPsum Score >=5":"1","Open-Proxy IPs":"0","Data-Shield IPs":"7","Talos 2024 IPs":"0","Multi-list IPs":"6","Listed-IP Country Mix":"PL:27"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS212913","ASN Number":"212913","Network Name":"TIMEHOST-AS TIME-HOST LTD","Aliases":"TIME-HOST LTD","Provider Family":"time-host.net","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.09","ipapi Rank":"711","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #711 with 19.09% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"3","Current Listed IPs":"10","IPsum IPs":"5","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"2","Data-Shield IPs":"7","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"RU:8, GB:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS213488","ASN Number":"213488","Network Name":"INOXWEB Mustafa Gunes trading as Inoxweb Datacenter ve Hosting Bilisim Teknolojileri","Aliases":"Mustafa Gunes trading as Inoxweb Datacen","Provider Family":"inoxweb.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"99.22","ipapi Rank":"462","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #462 with 99.22% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"TR:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS213945","ASN Number":"213945","Network Name":"AS213945 DATA HOME YAZILIM BILGI TEKNOLOJILERI TICARET LIMITED SIRKETI","Aliases":"DATA HOME YAZILIM BILGI TEKNOLOJILERI TI","Provider Family":"datahome.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"29.3","ipapi Rank":"587","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #587 with 29.3% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS213954","ASN Number":"213954","Network Name":"GTS-AS Global Transit Systems LLC","Aliases":"Global Transit Systems LLC","Provider Family":"globaltransitsystems.online","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"36.72","ipapi Rank":"549","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #549 with 36.72% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"1","Current Listed IPs":"29","IPsum IPs":"29","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"DE:10, UA:9, GB:4, FR:3, SE:2, PL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS214154","ASN Number":"214154","Network Name":"corentindoulet-as Corentin DOULET","Aliases":"Corentin DOULET","Provider Family":"geniusweer.com","RIR Country Code":"FR","Country Name":"France","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"40.63","ipapi Rank":"538","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #538 with 40.63% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS214762","ASN Number":"214762","Network Name":"MATHOST Sebastian Stefanek trading as MatHost.eu","Aliases":"Sebastian Stefanek trading as MatHost.eu","Provider Family":"mathost.eu","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"32.62","ipapi Rank":"572","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #572 with 32.62% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS215238","ASN Number":"215238","Network Name":"ONEMBILISIM IRFAN TUGRA ONEM","Aliases":"IRFAN TUGRA ONEM","Provider Family":"","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"54.99","ipapi Rank":"501","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #501 with 54.99% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"TR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS215703","ASN Number":"215703","Network Name":"FREAKHOSTING FREAKHOSTING LTD","Aliases":"","Provider Family":"FREAKHOSTING FREAKHOSTING LTD","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira ransomware targeting SonicWall SSL VPN","Last Evidence":"2025-09-22","Source IDs":"N06, N01","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS215703 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch ended 2026-03-21: 1 campaign (N06), newest report 2025-09-22. Stepped down T2 to T4 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"20","IPsum IPs":"4","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"11","Data-Shield IPs":"6","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"DE:19, PL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS216193","ASN Number":"216193","Network Name":"AS-HYPERION-CLOUD Hyperion Cloud SAS","Aliases":"Hyperion Cloud SAS","Provider Family":"hyperion.cloud","RIR Country Code":"FR","Country Name":"France","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"23.63","ipapi Rank":"643","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #643 with 23.63% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS216473","ASN Number":"216473","Network Name":"net-host Bashinskii Vadim Ruslanovich","Aliases":"Bashinskii Vadim Ruslanovich","Provider Family":"net-host.org","RIR Country Code":"KZ","Country Name":"Kazakhstan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"53.52","ipapi Rank":"502","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #502 with 53.52% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"2","Current Listed IPs":"6","IPsum IPs":"5","IPsum Score >=3":"1","IPsum Score >=5":"1","Open-Proxy IPs":"0","Data-Shield IPs":"6","Talos 2024 IPs":"0","Multi-list IPs":"5","Listed-IP Country Mix":"FI:6"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS265919","ASN Number":"265919","Network Name":"AS265919 - BB Host LTDA","Aliases":"BB Host LTDA","Provider Family":"bbhost.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"23.66","ipapi Rank":"641","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #641 with 23.66% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"2","Current Listed IPs":"3","IPsum IPs":"2","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"BR:3"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS266842","ASN Number":"266842","Network Name":"AS266842 - HNHOSTING.NET S.A.","Aliases":"HNHOSTING.NET S.A.","Provider Family":"hnhosting.net","RIR Country Code":"HN","Country Name":"Honduras","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"31.56","ipapi Rank":"576","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #576 with 31.56% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS268433","ASN Number":"268433","Network Name":"AS268433 - MGCLOUD SOLUCOES EM TIC LTDA - ME","Aliases":"MGCLOUD SOLUCOES EM TIC LTDA - ME","Provider Family":"mgcloud.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"188","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #188 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS272096","ASN Number":"272096","Network Name":"AS272096 - PACKETHUB S.A.","Aliases":"PacketHub S.A.","Provider Family":"PacketHub","RIR Country Code":"PA","Country Name":"Panama","Geography Scope":"Foreign","Provider Legal Country":"Panama","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Commercial VPN / hosting / proxy","Category":"Commercial VPN / anonymizer infrastructure","Evidence Level":"Medium","FP Risk":"Medium-High","Recommended Use":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"NordVPN-associated egress; EvilTokens token replay; exploitation and DDoS observations","Last Evidence":"2026-09-15","Source IDs":"N15, N16, N29, N30, N31, N01","Evidence Summary":"PacketHub S.A. operates global hosting infrastructure associated with NordVPN exit traffic. Published reporting observed PacketHub infrastructure in token replay, exploitation, and DDoS activity. Monitor unexpected employee logins; there is no evidence of provider complicity.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS395092","ASN Number":"395092","Network Name":"SHOCK-1 - Shock Hosting LLC","Aliases":"","Provider Family":"SHOCK-1","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Related provider or broad shared-service context","Evidence Level":"Context","FP Risk":"Medium","Recommended Use":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N01","Evidence Summary":"Active related network for SHOCK-1. No direct provider-level malicious designation was established; retain as enabled T2 monitoring context and require device, session, event-country, or post-authentication corroboration.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"206","IPsum IPs":"4","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"200","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"US:203, JP:1, SG:1, ZA:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS395898","ASN Number":"395898","Network Name":"TND - TND, LLC","Aliases":"TND, LLC","Provider Family":"tnddesk.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"31.81","ipapi Rank":"575","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #575 with 31.81% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS396356","ASN Number":"396356","Network Name":"LATITUDE-SH - Latitude.sh","Aliases":"","Provider Family":"LATITUDE-SH","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira ransomware targeting SonicWall SSL VPN","Last Evidence":"2025-09-22","Source IDs":"N06, N01","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS396356 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Analyst Notes":"Campaign watch ended 2026-03-21: 1 campaign (N06), newest report 2025-09-22. Stepped down T2 to T4 on 2026-10-07 when the ladder was applied retroactively. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS397006","ASN Number":"397006","Network Name":"MULLCLOUD - Mullcloud LLC","Aliases":"Mullcloud LLC","Provider Family":"mullcloud.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S02, S03, N01","Evidence Summary":"This ASN appeared in the Very High band at rank #574 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T2 High","ASN":"AS397702","ASN Number":"397702","Network Name":"SSSS - 1776 Solutions, LLC","Aliases":"1776 Solutions, LLC","Provider Family":"usips.org","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Very High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"28.52","ipapi Rank":"591","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #591 with 28.52% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS399629","ASN Number":"399629","Network Name":"BLNWX - BL Networks","Aliases":"","Provider Family":"BLNWX","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Console Chaos FortiGate management-interface exploitation","Last Evidence":"2025-01-10","Source IDs":"N09, N01","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS399629 across Console Chaos FortiGate management-interface exploitation. This does not implicate the provider or every tenant.","Analyst Notes":"Stepped down T2 to T4 on 2026-10-07: N09 reports FortiGate management-interface exploitation, which is not identity or VPN-authentication abuse, so it gives no campaign-watch basis. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"45","IPsum IPs":"36","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"6","Data-Shield IPs":"12","Talos 2024 IPs":"0","Multi-list IPs":"9","Listed-IP Country Mix":"NL:16, US:15, GB:8, RO:5, SG:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS8560","ASN Number":"8560","Network Name":"IONOS-AS IONOS SE","Aliases":"","Provider Family":"IONOS","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Related provider or broad shared-service context","Evidence Level":"Context","FP Risk":"Medium","Recommended Use":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N01","Evidence Summary":"Active related network for IONOS. No direct provider-level malicious designation was established; retain as enabled T3 risk context and require at least one corroborating identity or behavioral anomaly.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"712","IPsum IPs":"521","IPsum Score >=3":"31","IPsum Score >=5":"18","Open-Proxy IPs":"49","Data-Shield IPs":"280","Talos 2024 IPs":"0","Multi-list IPs":"138","Listed-IP Country Mix":"DE:354, ES:102, US:99, GB:92, FR:64, AT:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS9009","ASN Number":"9009","Network Name":"M247 M247 Europe SRL","Aliases":"M247; M247 LTD; m247.com; M247 Europe SRL","Provider Family":"","RIR Country Code":"RO","Country Name":"Romania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Large hosting, cloud, VPN-server and network-infrastructure provider","Category":"Legacy hosting/VPS watchlist","Evidence Level":"Medium: malware-hosting telemetry; not current ASN-DROP","FP Risk":"Very High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"S05, X068, X069, N01","Evidence Summary":"RIPEstat currently sees AS9009 announced. M247 markets hosting, cloud, dedicated and VPN servers. URLhaus has recorded malware-distribution URLs on AS9009 and reports a poor average takedown time, but the ASN is broad and is not in current Spamhaus ASN-DROP. Do not equate provider presence with provider complicity.","Analyst Notes":"Useful as a hosting-origin signal for human sign-ins, but too broad for standalone blocking or paging.","Current Community Feed Count":"3","Current Listed IPs":"635","IPsum IPs":"256","IPsum Score >=3":"20","IPsum Score >=5":"4","Open-Proxy IPs":"263","Data-Shield IPs":"198","Talos 2024 IPs":"6","Multi-list IPs":"88","Listed-IP Country Mix":"CA:244, DE:59, FR:35, GB:34, US:29, SG:25, ES:22, RO:19"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS11938","ASN Number":"11938","Network Name":"ABANTU - NCRYPTD LLC","Aliases":"NCRYPTD; ABANTU","Provider Family":"","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Small infrastructure/hosting network","Category":"Legacy hosting/VPS watchlist","Evidence Level":"None","FP Risk":"Medium","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S05, X015, N01","Evidence Summary":"The ASN is active, but no reliable explicit current malicious-use or bulletproof-hosting evidence was verified. The operator name alone is not evidence.","Analyst Notes":"If user logins from small infrastructure ASNs are out of policy, score them as hosting-origin anomalies but do not call this network malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS12876","ASN Number":"12876","Network Name":"AS12876 Scaleway SAS","Aliases":"","Provider Family":"Scaleway","RIR Country Code":"FR","Country Name":"France","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Related provider or broad shared-service context","Evidence Level":"Context","FP Risk":"Medium","Recommended Use":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N01","Evidence Summary":"Active related network for Scaleway. No direct provider-level malicious designation was established; retain as enabled T3 risk context and require at least one corroborating identity or behavioral anomaly.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"321","IPsum IPs":"231","IPsum Score >=3":"39","IPsum Score >=5":"10","Open-Proxy IPs":"40","Data-Shield IPs":"125","Talos 2024 IPs":"2","Multi-list IPs":"77","Listed-IP Country Mix":"FR:256, NL:58, PL:7"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS14061","ASN Number":"14061","Network Name":"DIGITALOCEAN-ASN - DigitalOcean, LLC","Aliases":"","Provider Family":"DigitalOcean","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Published campaign infrastructure in shared hosting or VPN space","Evidence Level":"Medium-High","FP Risk":"Medium","Recommended Use":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Akira ransomware targeting SonicWall SSL VPN; Console Chaos FortiGate management-interface exploitation","Last Evidence":"2025-09-22","Source IDs":"N06, N09, N01","Evidence Summary":"Published reporting includes 5 time-bounded indicators attributed to or currently mapped to AS14061 across Akira ransomware targeting SonicWall SSL VPN; Console Chaos FortiGate management-interface exploitation. This does not implicate the provider or every tenant.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"8074","IPsum IPs":"4989","IPsum Score >=3":"464","IPsum Score >=5":"65","Open-Proxy IPs":"478","Data-Shield IPs":"4976","Talos 2024 IPs":"0","Multi-list IPs":"2368","Listed-IP Country Mix":"US:4155, DE:1087, SG:975, GB:519, NL:488, IN:376, CA:290, AU:184"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS17497","ASN Number":"17497","Network Name":"LGHL-AS-AP - Liasail Global Hongkong Limited","Aliases":"liasail global hongkong limited","Provider Family":"liasail.com","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.22","ipapi Rank":"823","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #823 with 15.22% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"3","Current Listed IPs":"4","IPsum IPs":"3","IPsum Score >=3":"1","IPsum Score >=5":"1","Open-Proxy IPs":"1","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"US:2, AE:1, HK:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS20473","ASN Number":"20473","Network Name":"AS-VULTR - The Constant Company, LLC","Aliases":"","Provider Family":"Vultr","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Unknown / review","Category":"Broad VPS cloud with exact ransomware and management-interface IOCs","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as context for interactive sign-ins, VPN authentication, and management traffic. Require exact IOC or behavioral corroboration because Vultr is a broad multi-tenant cloud.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Gamaredon / Primitive Bear","Last Evidence":"2022-02-03","Source IDs":"S08, N01, N06, N07, N09","Evidence Summary":"Three short-lived Gamaredon C2 IPs were reported in Vultr. Disable ASN-wide alerts and retain the exact historical IPs.","Analyst Notes":"","Current Community Feed Count":"3","Current Listed IPs":"418","IPsum IPs":"234","IPsum Score >=3":"10","IPsum Score >=5":"2","Open-Proxy IPs":"134","Data-Shield IPs":"91","Talos 2024 IPs":"1","Multi-list IPs":"41","Listed-IP Country Mix":"US:155, JP:51, SG:42, DE:27, NL:26, AU:20, GB:17, FR:14"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS20709","ASN Number":"20709","Network Name":"TICOM-AS Techinform Ltd","Aliases":"Techinform Ltd","Provider Family":"ticom.net","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"20.7","ipapi Rank":"678","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #678 with 20.7% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS20724","ASN Number":"20724","Network Name":"GLOBALTELEHOST GlobalTeleHost Corp.","Aliases":"GlobalTeleHost Corp.; GLOBALTELEHOST","Provider Family":"globaltelehost.com","RIR Country Code":"CA","Country Name":"Canada","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Former ASN-DROP; hosting and botnet-C2 context","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a sign-in risk multiplier with device, MFA, session, event-country, or post-authentication anomalies. Do not treat delisting as safety.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, N42","Evidence Summary":"Present in the 2026-09-15 ASN-DROP snapshot and absent from the 2026-09-29 snapshot; delisting does not establish benignness. Spamhaus H1 2026 reporting identified GlobalTeleHost among newly prominent botnet C2 networks; counts are not normalized by provider size.","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS22295","ASN Number":"22295","Network Name":"ADVIN - Advin Services LLC","Aliases":"Advin Services; ADVIN; Advin Services LLC","Provider Family":"advinservers.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Weak","FP Risk":"Medium","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.17","ipapi Rank":"971","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, S05, X019, X020, N01","Evidence Summary":"ThreatFox reports a small number of recent malware IOCs on AS22295. That is useful malicious-use telemetry but does not show persistence, abuse tolerance, or provider complicity. ipapi.is ranks this hosting ASN #956 with 12.26% observed abuse concentration (High).","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious. Treat as an uncommon hosting/privacy origin and combine with behavioral identity signals.","Current Community Feed Count":"3","Current Listed IPs":"12","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"11","Talos 2024 IPs":"0","Multi-list IPs":"3","Listed-IP Country Mix":"US:12"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS24940","ASN Number":"24940","Network Name":"HETZNER-AS Hetzner Online GmbH","Aliases":"","Provider Family":"Hetzner","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Related provider or broad shared-service context","Evidence Level":"Context","FP Risk":"Medium","Recommended Use":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N01","Evidence Summary":"Active related network for Hetzner. No direct provider-level malicious designation was established; retain as enabled T3 risk context and require at least one corroborating identity or behavioral anomaly.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"1810","IPsum IPs":"1199","IPsum Score >=3":"17","IPsum Score >=5":"5","Open-Proxy IPs":"308","Data-Shield IPs":"446","Talos 2024 IPs":"1","Multi-list IPs":"144","Listed-IP Country Mix":"DE:1242, FI:568"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS26496","ASN Number":"26496","Network Name":"AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC","Aliases":"GoDaddy; PAH-INC; GoDaddy.com, LLC","Provider Family":"","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Large shared web-hosting and cloud network","Category":"Legacy hosting/VPS watchlist","Evidence Level":"Weak","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2024-08-19","Source IDs":"S05, X011, X012, N01","Evidence Summary":"Positive Technologies mapped a Lazarus campaign C2 IOC to AS26496, and abuse.ch has observed malware URLs on the ASN. These show tenant abuse on a very large shared provider, not systematic bulletproof behavior or provider complicity.","Analyst Notes":"GoDaddy is an appropriate anomalous-user-login signal but a poor blanket block because shared hosting, parked domains and integrations can create false positives.","Current Community Feed Count":"3","Current Listed IPs":"62","IPsum IPs":"30","IPsum Score >=3":"6","IPsum Score >=5":"2","Open-Proxy IPs":"11","Data-Shield IPs":"40","Talos 2024 IPs":"0","Multi-list IPs":"19","Listed-IP Country Mix":"SG:37, US:17, JP:8"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS26548","ASN Number":"26548","Network Name":"PUREVOLTAGE-INC - PureVoltage Hosting Inc.","Aliases":"PureVoltage Hosting Inc.","Provider Family":"purevoltage.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.85","ipapi Rank":"695","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #695 with 19.85% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"2","Current Listed IPs":"52","IPsum IPs":"49","IPsum Score >=3":"2","IPsum Score >=5":"2","Open-Proxy IPs":"0","Data-Shield IPs":"5","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"US:52"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS26701","ASN Number":"26701","Network Name":"AADS - NCRYPTD LLC","Aliases":"NCRYPTD; AADS","Provider Family":"","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Small infrastructure/hosting network","Category":"Legacy hosting/VPS watchlist","Evidence Level":"None","FP Risk":"Medium","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S05, X022, N01","Evidence Summary":"The ASN is active, but no reliable explicit current malicious-use or bulletproof-hosting evidence was verified. Do not infer maliciousness from the operator name or adjacency.","Analyst Notes":"Small hosting/infrastructure origin may raise login risk, but the dirty label is currently uncorroborated.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS30860","ASN Number":"30860","Network Name":"YURTEH-AS Virtual Systems LLC","Aliases":"Virtual Systems LLC","Provider Family":"vsys.host","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S02, S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #859 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"3","Current Listed IPs":"22","IPsum IPs":"8","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"11","Data-Shield IPs":"7","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"UA:22"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T3 Context","ASN":"AS34202","ASN Number":"34202","Network Name":"CLOUVIDER-THN2 Clouvider Limited","Aliases":"","Provider Family":"Clouvider","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"United Kingdom","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Related Clouvider hosting / transit network","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N10, N11, N12, N13, N14, N01","Evidence Summary":"Active Clouvider-related ASN without direct reviewed identity-attack evidence at the ASN level. Kept disabled as provider-family context; do not infer malicious operation or provider complicity.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS34828","ASN Number":"34828","Network Name":"Domainhizmetleri-Com DH Bulut Bilisim Anonim Sirketi","Aliases":"DH Bulut Bilisim Anonim Sirketi","Provider Family":"domainhizmetleri.com","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S02, S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #755 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS35048","ASN Number":"35048","Network Name":"BITERIKA-AS Biterika Group LLC","Aliases":"Biterika Group LLC","Provider Family":"biterika.com","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.74","ipapi Rank":"748","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #748 with 17.74% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"1","Current Listed IPs":"42","IPsum IPs":"42","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RU:42"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS35346","ASN Number":"35346","Network Name":"EUROTELECOM SC ITNS.NET SRL","Aliases":"ITNS.NET; Eurotelecom","Provider Family":"","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"ISP, transit and hosting network","Category":"Legacy hosting/VPS watchlist","Evidence Level":"None","FP Risk":"Medium","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S05, X027, N01","Evidence Summary":"No reliable explicit current report establishing systematic malicious use or bulletproof behavior was verified. Community abuse counters were excluded as evidence of provider complicity.","Analyst Notes":"Hosting/transit origin can contribute to a risk score, but this ASN lacks corroboration for a dirty-network label.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"MD:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS40403","ASN Number":"40403","Network Name":"RCS-ASN - Rocks Computer Services, LLC","Aliases":"RCS-ASN; therocksnet.com; MARITIME-APPLIED-PHYSICS-CORPORATION (historical holder); Rocks Computer Services, LLC","Provider Family":"","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"regional ISP / managed network","Category":"Legacy hosting/VPS watchlist","Evidence Level":"low","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"S05, X029, N01","Evidence Summary":"ARIN currently assigns AS40403 to Rocks Computer Services, LLC and RIPEstat shows it is announced. A public historical ASN list records the older MARITIME-APPLIED-PHYSICS-CORPORATION identity, demonstrating holder churn. It is absent from current Spamhaus ASN-DROP, and no credible current BPH or campaign evidence was located for the present holder.","Analyst Notes":"Do not carry reputation from the prior ASN holder into the current regional ISP. Use hosting/ASN context only when authentication behavior supplies independent risk.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS41745","ASN Number":"41745","Network Name":"FORTIS-AS Baykov Ilya Sergeevich","Aliases":"Baykov Ilya Sergeevich","Provider Family":"ib.systems","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.01","ipapi Rank":"984","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #984 with 12.01% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"3","Current Listed IPs":"96","IPsum IPs":"54","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"37","Data-Shield IPs":"35","Talos 2024 IPs":"0","Multi-list IPs":"30","Listed-IP Country Mix":"NL:18, FI:16, DE:13, US:11, FR:8, LV:8, SE:7, RU:5"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T3 Context","ASN":"AS43878","ASN Number":"43878","Network Name":"EUROPE-CONNECTED Clouvider Limited","Aliases":"","Provider Family":"Clouvider","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"United Kingdom","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Related Clouvider hosting / transit network","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N10, N11, N12, N13, N14, N01","Evidence Summary":"Active Clouvider-related ASN without direct reviewed identity-attack evidence at the ASN level. Kept disabled as provider-family context; do not infer malicious operation or provider complicity.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS45753","ASN Number":"45753","Network Name":"NETSEC-HK - Netsec Limited","Aliases":"NETSEC-HK; Simcentric Solutions Limited; Network and Security Solutions Limited; Netsec Limited","Provider Family":"","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"large shared hosting / data-center provider","Category":"Legacy hosting/VPS watchlist","Evidence Level":"medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-03-25","Source IDs":"S05, X041, X042, X043, N01","Evidence Summary":"Silent Push found AS45753 among Asian hosting ranges containing FUNNULL IPs actively used in live scam/phishing campaigns. GreyNoise later observed 8,759 apparent new scanner source IPs from AS45753, but 99.96% never completed a TCP handshake and only one was classified malicious; GreyNoise calls this a 'ghost fleet' and recommends behavioral tracking. This is credible evidence of specific abuse on shared hosting, not evidence that Netsec is a bulletproof host or that the whole ASN is malicious.","Analyst Notes":"A login from this hosting ASN is useful risk context, but ASN-only blocking would overreach. Combine with impossible travel, unfamiliar device, password spray, proxy/VPN and IP-level threat intelligence.","Current Community Feed Count":"3","Current Listed IPs":"20","IPsum IPs":"15","IPsum Score >=3":"1","IPsum Score >=5":"1","Open-Proxy IPs":"1","Data-Shield IPs":"11","Talos 2024 IPs":"0","Multi-list IPs":"7","Listed-IP Country Mix":"HK:20"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS47272","ASN Number":"47272","Network Name":"HYEHOST - HYEHOST LLC","Aliases":"HYEHOST LLC","Provider Family":"hyehost.org","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.51","ipapi Rank":"845","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #845 with 14.51% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS48031","ASN Number":"48031","Network Name":"XServerCloud Ivanov Vitaliy Sergeevich","Aliases":"XServerCloud; xserver.cloud; Ivanov Vitaliy Sergeevich (spam Russia); Ivanov Vitaliy Sergeevich","Provider Family":"","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"VPS and dedicated hosting","Category":"Legacy hosting/VPS watchlist","Evidence Level":"Low: provider and registry classification only","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"S05, X061, X062, N01","Evidence Summary":"RIPEstat currently sees AS48031 announced. Public network profiles identify XServerCloud as a VPS and dedicated-server provider. It is not in current Spamhaus ASN-DROP, and no strong current BPH designation was verified.","Analyst Notes":"Use as a server-hosting origin signal combined with interactive user, new device, impossible travel, or other identity anomalies.","Current Community Feed Count":"1","Current Listed IPs":"29","IPsum IPs":"29","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"TM:25, PL:2, SA:1, UA:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS51167","ASN Number":"51167","Network Name":"CONTABO Contabo GmbH","Aliases":"","Provider Family":"Contabo","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Related provider or broad shared-service context","Evidence Level":"Context","FP Risk":"Medium","Recommended Use":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N01","Evidence Summary":"Active related network for Contabo. No direct provider-level malicious designation was established; retain as enabled T3 risk context and require at least one corroborating identity or behavioral anomaly.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"1226","IPsum IPs":"702","IPsum Score >=3":"47","IPsum Score >=5":"19","Open-Proxy IPs":"174","Data-Shield IPs":"582","Talos 2024 IPs":"1","Multi-list IPs":"232","Listed-IP Country Mix":"DE:944, GB:248, US:25, IN:4, FR:3, AU:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS54203","ASN Number":"54203","Network Name":"NETPROTECT-SP - Strong Technology, LLC.","Aliases":"","Provider Family":"Strong Technology / NetProtect","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"United States","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Commercial VPN / hosting / proxy","Category":"Commercial VPN / proxy egress observed in brute-force campaign","Evidence Level":"Medium","FP Risk":"Medium-High","Recommended Use":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Cisco Talos 2024 VPN and SSH brute-force activity","Last Evidence":"2026-09-15","Source IDs":"N35, N36, N01","Evidence Summary":"Time-matched RouteViews mapping attributes 178 IPs across 34 /24s from the Cisco Talos April 2024 brute-force IOC set to this Strong Technology / NetProtect ASN. Treat as commercial VPN/proxy egress context; no provider complicity is asserted.","Analyst Notes":"Current IP-to-AS mappings differ from the campaign-time mapping; do not use current feed counts as historical attribution.","Current Community Feed Count":"2","Current Listed IPs":"5","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"4","Multi-list IPs":"1","Listed-IP Country Mix":"US:5"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T3 Context","ASN":"AS57724","ASN Number":"57724","Network Name":"DDOS-GUARD DDOS-GUARD LTD","Aliases":"","Provider Family":"DDoS-Guard","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Published campaign infrastructure in shared hosting or VPN space","Evidence Level":"Medium-High","FP Risk":"Medium","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"UNC6671 multi-brand vishing, AiTM, and SaaS extortion","Last Evidence":"2026-08-06","Source IDs":"N17, N01","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS57724 across UNC6671 multi-brand vishing, AiTM, and SaaS extortion. This does not implicate the provider or every tenant.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"GB:1, RU:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS57852","ASN Number":"57852","Network Name":"csp CLOUD S P SARL","Aliases":"CLOUD S P SARL","Provider Family":"cloudsp-lb.com","RIR Country Code":"LB","Country Name":"Lebanon","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.77","ipapi Rank":"747","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #747 with 17.77% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS58349","ASN Number":"58349","Network Name":"INNETRA-AS Elna Paulette Valentin trading as INNETRA PC","Aliases":"INNETRA-AS; INNETRA; innetra.com; Elna Paulette Valentin trading as INNETRA PC","Provider Family":"","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"VPS, dedicated hosting and IP transit","Category":"Legacy hosting/VPS watchlist","Evidence Level":"Low: provider and registry classification only","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"S05, X059, X060, N01","Evidence Summary":"RIPEstat currently sees AS58349 announced. INNETRA publicly sells protected VPS, dedicated servers, and IP transit. The ASN is not in current Spamhaus ASN-DROP, and no strong current BPH designation was found.","Analyst Notes":"A human interactive sign-in from generic server hosting is unusual, but ASN alone is not evidence of compromise.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"NL:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T3 Context","ASN":"AS60262","ASN Number":"60262","Network Name":"PANQ Panq B.V.","Aliases":"","Provider Family":"Panq","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"Netherlands","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Commercial VPN / hosting / proxy","Category":"Related provider or broad shared-service context","Evidence Level":"Context","FP Risk":"Medium","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N29, N30, N31, N01","Evidence Summary":"Active related network for Panq. No direct provider-level malicious designation was established; retain as disabled family or shared-service context.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS61003","ASN Number":"61003","Network Name":"GLOBALTELEHOST GlobalTeleHost Corp.","Aliases":"GlobalTeleHost Corp.; GLOBALTELEHOST","Provider Family":"globaltelehost.com","RIR Country Code":"CA","Country Name":"Canada","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Former ASN-DROP; hosting and botnet-C2 context","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a sign-in risk multiplier with device, MFA, session, event-country, or post-authentication anomalies. Do not treat delisting as safety.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, N42","Evidence Summary":"Present in the 2026-09-15 ASN-DROP snapshot and absent from the 2026-09-29 snapshot; delisting does not establish benignness. Spamhaus H1 2026 reporting identified GlobalTeleHost among newly prominent botnet C2 networks; counts are not normalized by provider size.","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS61254","ASN Number":"61254","Network Name":"ESTOXY-OU ESTOXY OU","Aliases":"ESTOXY OU","Provider Family":"estoxy.com","RIR Country Code":"EE","Country Name":"Estonia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S02, S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #818 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"3","Current Listed IPs":"34","IPsum IPs":"15","IPsum Score >=3":"2","IPsum Score >=5":"0","Open-Proxy IPs":"9","Data-Shield IPs":"16","Talos 2024 IPs":"0","Multi-list IPs":"6","Listed-IP Country Mix":"NL:23, FR:11"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS62563","ASN Number":"62563","Network Name":"AS-GLOBALTELEHOST - GLOBALTELEHOST Corp.","Aliases":"GLOBALTELEHOST Corp.; AS-GLOBALTELEHOST","Provider Family":"globaltelehost.com","RIR Country Code":"CA","Country Name":"Canada","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Former ASN-DROP; hosting and botnet-C2 context","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a sign-in risk multiplier with device, MFA, session, event-country, or post-authentication anomalies. Do not treat delisting as safety.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, N42","Evidence Summary":"Present in the 2026-09-15 ASN-DROP snapshot and absent from the 2026-09-29 snapshot; delisting does not establish benignness. Spamhaus H1 2026 reporting identified GlobalTeleHost among newly prominent botnet C2 networks; counts are not normalized by provider size.","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"3","Current Listed IPs":"4","IPsum IPs":"3","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"CA:4"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS62651","ASN Number":"62651","Network Name":"NETPROTECT-DP - Strong Technology, LLC.","Aliases":"","Provider Family":"Strong Technology / NetProtect","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"United States","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Commercial VPN / hosting / proxy","Category":"Commercial VPN / proxy egress observed in brute-force campaign","Evidence Level":"Medium","FP Risk":"Medium-High","Recommended Use":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Cisco Talos 2024 VPN and SSH brute-force activity","Last Evidence":"2026-09-15","Source IDs":"N35, N36, N01","Evidence Summary":"Time-matched RouteViews mapping attributes 130 IPs across 37 /24s from the Cisco Talos April 2024 brute-force IOC set to this Strong Technology / NetProtect ASN. Treat as commercial VPN/proxy egress context; no provider complicity is asserted.","Analyst Notes":"Current IP-to-AS mappings differ from the campaign-time mapping; do not use current feed counts as historical attribution.","Current Community Feed Count":"2","Current Listed IPs":"242","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"239","Multi-list IPs":"0","Listed-IP Country Mix":"US:68, FR:37, ES:31, CA:19, GB:7, IE:6, PT:6, SE:6"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS63023","ASN Number":"63023","Network Name":"AS-GLOBALTELEHOST - GTHost","Aliases":"GTHost; AS-GLOBALTELEHOST","Provider Family":"globaltelehost.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Former ASN-DROP; hosting and botnet-C2 context","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a sign-in risk multiplier with device, MFA, session, event-country, or post-authentication anomalies. Do not treat delisting as safety.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, N42","Evidence Summary":"Present in the 2026-09-15 ASN-DROP snapshot and absent from the 2026-09-29 snapshot; delisting does not establish benignness. Spamhaus H1 2026 reporting identified GlobalTeleHost among newly prominent botnet C2 networks; counts are not normalized by provider size.","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS63737","ASN Number":"63737","Network Name":"VIETSERVER-AS-VN - VIETSERVER SERVICES TECHNOLOGY COMPANY LIMITED","Aliases":"VIETSERVER SERVICES TECHNOLOGY COMPANY L","Provider Family":"vietserver.vn","RIR Country Code":"VN","Country Name":"Vietnam","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.32","ipapi Rank":"760","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #760 with 17.32% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"3","Current Listed IPs":"27","IPsum IPs":"9","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"5","Data-Shield IPs":"22","Talos 2024 IPs":"0","Multi-list IPs":"9","Listed-IP Country Mix":"VN:27"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS63949","ASN Number":"63949","Network Name":"AKAMAI-LINODE-AP - Akamai Connected Cloud","Aliases":"","Provider Family":"Akamai Connected Cloud","RIR Country Code":"SG","Country Name":"Singapore","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Related provider or broad shared-service context","Evidence Level":"Context","FP Risk":"Medium","Recommended Use":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N01","Evidence Summary":"Active related network for Akamai Connected Cloud. No direct provider-level malicious designation was established; retain as enabled T3 risk context and require at least one corroborating identity or behavioral anomaly.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"1684","IPsum IPs":"1332","IPsum Score >=3":"173","IPsum Score >=5":"39","Open-Proxy IPs":"105","Data-Shield IPs":"1024","Talos 2024 IPs":"1","Multi-list IPs":"778","Listed-IP Country Mix":"US:1290, SG:82, DE:58, GB:55, JP:48, CA:40, IN:24, ID:23"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS64080","ASN Number":"64080","Network Name":"SYN-UK SYN LTD","Aliases":"SYN LTD","Provider Family":"syn.one","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.2","ipapi Rank":"824","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #824 with 15.2% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS64107","ASN Number":"64107","Network Name":"AS64107 - RACK SPHERE HOSTING S.A.","Aliases":"RACK SPHERE HOSTING S.A.","Provider Family":"racksphere.io","RIR Country Code":"PA","Country Name":"Panama","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.45","ipapi Rank":"853","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #853 with 14.45% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"2","Current Listed IPs":"4","IPsum IPs":"4","IPsum Score >=3":"3","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"4","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"NL:4"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS133244","ASN Number":"133244","Network Name":"CISPVLTD-AS - Craze It Solutions Pvt. Ltd.","Aliases":"Craze It Solutions Pvt. Ltd.","Provider Family":"crazetechnology.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"11.91","ipapi Rank":"991","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #991 with 11.91% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS133944","ASN Number":"133944","Network Name":"Trafficforce-Internet-Services trafficforce, UAB","Aliases":"trafficforce, UAB","Provider Family":"trafficforce.lt","RIR Country Code":"LT","Country Name":"Lithuania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S02, S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #979 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS135377","ASN Number":"135377","Network Name":"UCLOUD-HK-AS-AP - UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED","Aliases":"","Provider Family":"UCloud","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Related provider or broad shared-service context","Evidence Level":"Context","FP Risk":"Medium","Recommended Use":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N01","Evidence Summary":"Active related network for UCloud. No direct provider-level malicious designation was established; retain as enabled T3 risk context and require at least one corroborating identity or behavioral anomaly.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"1874","IPsum IPs":"1358","IPsum Score >=3":"561","IPsum Score >=5":"107","Open-Proxy IPs":"32","Data-Shield IPs":"1526","Talos 2024 IPs":"0","Multi-list IPs":"1036","Listed-IP Country Mix":"HK:722, US:535, TH:83, SG:75, JP:70, TW:51, GB:48, KR:48"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS135967","ASN Number":"135967","Network Name":"BKNS-AS-VN - Bach Kim Network solutions Join stock company","Aliases":"Bach Kim Network solutions Join stock co","Provider Family":"bkns.vn","RIR Country Code":"VN","Country Name":"Vietnam","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.69","ipapi Rank":"776","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #776 with 16.69% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"3","Current Listed IPs":"20","IPsum IPs":"11","IPsum Score >=3":"2","IPsum Score >=5":"1","Open-Proxy IPs":"6","Data-Shield IPs":"10","Talos 2024 IPs":"0","Multi-list IPs":"7","Listed-IP Country Mix":"VN:20"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS150055","ASN Number":"150055","Network Name":"DIGISNAP-AS-IN - DIGITAL SNAP","Aliases":"DIGITAL SNAP","Provider Family":"digital-snap.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.8","ipapi Rank":"886","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #886 with 13.8% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"IN:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS152460","ASN Number":"152460","Network Name":"GREENHOST-AS-AP - Greenhost BV","Aliases":"Greenhost BV","Provider Family":"greenhost.net","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.52","ipapi Rank":"895","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #895 with 13.52% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS154701","ASN Number":"154701","Network Name":"CDS-AS-AP - Capitalonline Data Service (HK) Co., Limited","Aliases":"Capitalonline Data Service (HK) Co., Lim","Provider Family":"capitalonline.net","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.95","ipapi Rank":"797","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #797 with 15.95% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS197695","ASN Number":"197695","Network Name":"AS-REGRU \"Domain names registrar REG.RU\", Ltd","Aliases":"","Provider Family":"REG.RU","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / registrar infrastructure","Category":"Historical actor infrastructure concentration","Evidence Level":"High","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"ACTINIUM / Aqua Blizzard / Gamaredon","Last Evidence":"2022-02-04","Source IDs":"S07, S08, N01","Evidence Summary":"Microsoft observed more than 70% of 200-plus ACTINIUM operational IPs in AS197695; Unit 42 independently observed 131 of 136 recent downloader IPs there. Both characterize REG.RU as a legitimate provider.","Analyst Notes":"","Current Community Feed Count":"3","Current Listed IPs":"37","IPsum IPs":"14","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"13","Data-Shield IPs":"12","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"RU:37"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS198120","ASN Number":"198120","Network Name":"smart-host Smart Host Teknoloji Ithalat Ihracat Limited Sirketi","Aliases":"Smart Host Teknoloji Ithalat Ihracat Lim","Provider Family":"smart-host.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.23","ipapi Rank":"819","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #819 with 15.23% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS199829","ASN Number":"199829","Network Name":"Akronic-Network Akronic Network LTDA","Aliases":"Akronic Network LTDA","Provider Family":"akronic.network","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.69","ipapi Rank":"840","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #840 with 14.69% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"2","Current Listed IPs":"3","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:3"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS200509","ASN Number":"200509","Network Name":"SVINT-ASN Comlocal, S.L.","Aliases":"Comlocal, S.L.","Provider Family":"svint.net","RIR Country Code":"ES","Country Name":"Spain","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.87","ipapi Rank":"885","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #885 with 13.87% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS201801","ASN Number":"201801","Network Name":"ZEROSPACE Christian Wittenberg trading as Zerospace Cloud","Aliases":"Christian Wittenberg trading as Zerospac","Provider Family":"zerospace.cloud","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.84","ipapi Rank":"836","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #836 with 14.84% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"NL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS202044","ASN Number":"202044","Network Name":"Getechbrothers-Internet Getechbrothers, MB","Aliases":"Getechbrothers, MB","Provider Family":"getechbrothers.com","RIR Country Code":"LT","Country Name":"Lithuania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.89","ipapi Rank":"880","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #880 with 13.89% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"1","Current Listed IPs":"131","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"131","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"GB:131"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS202124","ASN Number":"202124","Network Name":"HAYPEM Haypem Iletisim Limited","Aliases":"Haypem Iletisim Limited","Provider Family":"macrogate.net","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.41","ipapi Rank":"790","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #790 with 16.41% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS202496","ASN Number":"202496","Network Name":"prienai-sciences-Internet trafficforce, UAB","Aliases":"trafficforce, UAB","Provider Family":"trafficforce.lt","RIR Country Code":"LT","Country Name":"Lithuania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.88","ipapi Rank":"714","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #714 with 18.88% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS202520","ASN Number":"202520","Network Name":"SKYPASS-AS SkyPass Solutions Sp. z o.o.","Aliases":"SkyPass Solutions Sp. z.o.o.","Provider Family":"skypass.tech","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business / hosting services","Category":"High abuse-concentration business/hosting context","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.37","ipapi Rank":"963","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #963 with 12.37% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious. ipapi.is changed the organization type from hosting to business on the current snapshot; tier and enablement are preserved pending independent review.","Current Community Feed Count":"2","Current Listed IPs":"11","IPsum IPs":"9","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"PL:11"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T3 Context","ASN":"AS202791","ASN Number":"202791","Network Name":"CLOUDSRV-ANY Clouvider Limited","Aliases":"","Provider Family":"Clouvider","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"United Kingdom","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Related Clouvider hosting / transit network","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N10, N11, N12, N13, N14, N01","Evidence Summary":"Active Clouvider-related ASN without direct reviewed identity-attack evidence at the ASN level. Kept disabled as provider-family context; do not infer malicious operation or provider complicity.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T3 Context","ASN":"AS202792","ASN Number":"202792","Network Name":"CLOUD-TRANSIT Clouvider Limited","Aliases":"","Provider Family":"Clouvider","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"United Kingdom","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Related Clouvider hosting / transit network","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N10, N11, N12, N13, N14, N01","Evidence Summary":"Active Clouvider-related ASN without direct reviewed identity-attack evidence at the ASN level. Kept disabled as provider-family context; do not infer malicious operation or provider complicity.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS203020","ASN Number":"203020","Network Name":"HostRoyale HostRoyale Technologies Pvt Ltd","Aliases":"","Provider Family":"HostRoyale","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"Medium-High","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"MuddyWater / BugSleep infrastructure cluster","Last Evidence":"2026-01-28","Source IDs":"N08, N01","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS203020 across MuddyWater / BugSleep infrastructure cluster. This does not implicate the provider or every tenant.","Analyst Notes":"Stepped down T3 to T4 on 2026-10-07: N08 reports MuddyWater BugSleep C2, which is not identity or VPN-authentication abuse, so it gives no campaign-watch basis. Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"169","IPsum IPs":"22","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"137","Data-Shield IPs":"2","Talos 2024 IPs":"9","Multi-list IPs":"1","Listed-IP Country Mix":"US:135, AL:6, IN:6, BE:4, FR:4, AU:2, CY:2, ES:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS203718","ASN Number":"203718","Network Name":"Astelon Astelon GmbH","Aliases":"Astelon GmbH","Provider Family":"astelon.net","RIR Country Code":"CH","Country Name":"Switzerland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S02, S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #993 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS204997","ASN Number":"204997","Network Name":"FIRSTBYTE-AS FIRST SERVER LIMITED","Aliases":"","Provider Family":"FIRST SERVER","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Related provider or broad shared-service context","Evidence Level":"Context","FP Risk":"Medium","Recommended Use":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"Reused VM, C2, and brute-force-as-a-service infrastructure","Last Evidence":"2026-09-15","Source IDs":"N19, N22, N01","Evidence Summary":"Active related network for FIRST SERVER. No direct provider-level malicious designation was established; retain as enabled T3 risk context and require at least one corroborating identity or behavioral anomaly.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"32","IPsum IPs":"16","IPsum Score >=3":"1","IPsum Score >=5":"1","Open-Proxy IPs":"15","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"RU:28, PL:2, GB:1, NL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS205090","ASN Number":"205090","Network Name":"FIRST-SERVER-EUROPE FIRST SERVER LIMITED","Aliases":"","Provider Family":"FIRST SERVER","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Published campaign infrastructure in shared hosting or VPN space","Evidence Level":"Medium-High","FP Risk":"Medium","Recommended Use":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Reverse-connection endpoint exposed with C2 and persistence tooling; Reused VM, C2, and brute-force-as-a-service infrastructure","Last Evidence":"2026-02-03","Source IDs":"N19, N22, N01","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS205090 across Reverse-connection endpoint exposed with C2 and persistence tooling. This does not implicate the provider or every tenant.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"22","IPsum IPs":"7","IPsum Score >=3":"1","IPsum Score >=5":"1","Open-Proxy IPs":"15","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"3","Listed-IP Country Mix":"RU:17, UA:3, PL:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS205964","ASN Number":"205964","Network Name":"code200-180 UAB code200","Aliases":"UAB code200","Provider Family":"code200.global","RIR Country Code":"LT","Country Name":"Lithuania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"11.93","ipapi Rank":"988","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #988 with 11.93% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T3 Context","ASN":"AS206136","ASN Number":"206136","Network Name":"CLOUDSRV-NORTH Clouvider Limited","Aliases":"","Provider Family":"Clouvider","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"United Kingdom","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-09-28","Network Type":"Shared hosting / VPS / cloud","Category":"Related Clouvider hosting / transit network","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N10, N11, N12, N13, N14, N01","Evidence Summary":"Active Clouvider-related ASN without direct reviewed identity-attack evidence at the ASN level. Kept disabled as provider-family context; do not infer malicious operation or provider complicity.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS206791","ASN Number":"206791","Network Name":"SBY-Telecom-AS Slobozhenyuk B.Y. PE","Aliases":"Slobozhenyuk B.Y. PE","Provider Family":"sby-telecom.info","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.23","ipapi Rank":"818","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #818 with 15.23% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"UA:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T3 Context","ASN":"AS206822","ASN Number":"206822","Network Name":"CLOUDNET Clouvider Limited","Aliases":"","Provider Family":"Clouvider","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"United Kingdom","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Related Clouvider hosting / transit network","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N10, N11, N12, N13, N14, N01","Evidence Summary":"Active Clouvider-related ASN without direct reviewed identity-attack evidence at the ASN level. Kept disabled as provider-family context; do not infer malicious operation or provider complicity.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T3 Context","ASN":"AS206848","ASN Number":"206848","Network Name":"UKCDN Clouvider Limited","Aliases":"","Provider Family":"Clouvider","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"United Kingdom","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Related Clouvider hosting / transit network","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N10, N11, N12, N13, N14, N01","Evidence Summary":"Active Clouvider-related ASN without direct reviewed identity-attack evidence at the ASN level. Kept disabled as provider-family context; do not infer malicious operation or provider complicity.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T3 Context","ASN":"AS207019","ASN Number":"207019","Network Name":"TNCL Clouvider Limited","Aliases":"","Provider Family":"Clouvider","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"United Kingdom","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Related Clouvider hosting / transit network","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N10, N11, N12, N13, N14, N01","Evidence Summary":"Active Clouvider-related ASN without direct reviewed identity-attack evidence at the ASN level. Kept disabled as provider-family context; do not infer malicious operation or provider complicity.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T3 Context","ASN":"AS207158","ASN Number":"207158","Network Name":"WORLDCDN Clouvider Limited","Aliases":"","Provider Family":"Clouvider","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"United Kingdom","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Related Clouvider hosting / transit network","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N10, N11, N12, N13, N14, N01","Evidence Summary":"Active Clouvider-related ASN without direct reviewed identity-attack evidence at the ASN level. Kept disabled as provider-family context; do not infer malicious operation or provider complicity.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS207350","ASN Number":"207350","Network Name":"Faratechnology Arshia Asadi","Aliases":"Arshia Asadi","Provider Family":"my.papiliohost.com","RIR Country Code":"IR","Country Name":"Iran","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.63","ipapi Rank":"807","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #807 with 15.63% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"IR:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS207569","ASN Number":"207569","Network Name":"I-SERVERS-NORTH-EU IHOR HOSTING LTD","Aliases":"I-SERVERS; IHOR HOSTING; PSERVERS; Power Servers","Provider Family":"","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"VPS/server hosting","Category":"Legacy hosting/VPS watchlist","Evidence Level":"Weak","FP Risk":"Medium","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S05, X009, X010, N01","Evidence Summary":"Current routing identifies an active server-hosting network. URLhaus has mapped malware-delivery URLs to AS207569, but the reviewed evidence is isolated abuse telemetry and is insufficient to characterize the provider as bulletproof or complicit.","Analyst Notes":"Useful as a hosting-origin signal, but escalate only with failed-login volume, unfamiliar device, impossible travel, or other risk evidence.","Current Community Feed Count":"3","Current Listed IPs":"24","IPsum IPs":"17","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"7","Data-Shield IPs":"4","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"FI:20, RU:3, UA:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS208981","ASN Number":"208981","Network Name":"DPC24 Data Center LLC","Aliases":"Data Center LLC","Provider Family":"dpc24.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.97","ipapi Rank":"830","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #830 with 14.97% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS209178","ASN Number":"209178","Network Name":"IPv4Superhub IPv4 Superhub Limited","Aliases":"IPv4 Superhub Limited","Provider Family":"ipv4superhub.com","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.5","ipapi Rank":"959","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #959 with 12.5% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS209207","ASN Number":"209207","Network Name":"DHOST-AS Digital Hosting Provider LLC","Aliases":"Digital Hosting Provider LLC","Provider Family":"dhost.su","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.43","ipapi Rank":"899","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #899 with 13.43% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"3","Current Listed IPs":"7","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"3","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"DE:6, NL:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS209671","ASN Number":"209671","Network Name":"QRATOR-SW Qrator Labs CZ s.r.o.","Aliases":"Qrator Labs CZ s.r.o.","Provider Family":"qrator.net","RIR Country Code":"CZ","Country Name":"Czechia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.51","ipapi Rank":"846","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #846 with 14.51% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS212890","ASN Number":"212890","Network Name":"AetherCloud ONEMAN NETWORK LIMITED","Aliases":"ONEMAN NETWORK LIMITED","Provider Family":"oneman.me","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"20.31","ipapi Rank":"685","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #685 with 20.31% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS213230","ASN Number":"213230","Network Name":"HETZNER-CLOUD2-AS Hetzner Online GmbH","Aliases":"HETZNER-CLOUD2-AS; Hetzner Cloud; hetzner.com; Hetzner Online GmbH","Provider Family":"","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Large public cloud and VPS hosting","Category":"Legacy hosting/VPS watchlist","Evidence Level":"Low: provider and registry classification only","FP Risk":"Very High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"S05, X063, X064, N01","Evidence Summary":"RIPEstat currently sees AS213230 announced. Hetzner's documentation confirms a public cloud and server platform. It is not in current Spamhaus ASN-DROP. Attackers can rent cloud instances, but there is no basis to label Hetzner itself malicious.","Analyst Notes":"Keep separate from high-confidence BPH. Alert only on interactive user sign-ins combined with local anomalies and allowlist known integrations.","Current Community Feed Count":"3","Current Listed IPs":"41","IPsum IPs":"19","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"14","Data-Shield IPs":"11","Talos 2024 IPs":"0","Multi-list IPs":"3","Listed-IP Country Mix":"US:41"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS214478","ASN Number":"214478","Network Name":"AS-SAKURACLOUDS Sakura Clouds LLC","Aliases":"Sakura Clouds LLC","Provider Family":"sakuraclouds.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.8","ipapi Rank":"770","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #770 with 16.8% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"US:1"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS214973","ASN Number":"214973","Network Name":"axst-io Apex Strata Ltd","Aliases":"Apex Strata Ltd","Provider Family":"apexstrata.ie","RIR Country Code":"IE","Country Name":"Ireland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.5","ipapi Rank":"958","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #958 with 12.5% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"1","Current Listed IPs":"4","IPsum IPs":"4","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"IE:4"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS215240","ASN Number":"215240","Network Name":"MICRODEX-AS Microdex UG (haftungsbeschraenkt)","Aliases":"Microdex UG; historical: Silent Connection Ltd","Provider Family":"","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-09-15","Network Type":"Small content/hosting network","Category":"Legacy hosting/VPS watchlist","Evidence Level":"Weak","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2025-05-01","Source IDs":"S05, X004, X006, X007, N01","Evidence Summary":"Excedo and Team Cymru reported severe abuse under the former holder Silent Connection Ltd. The current RIPE object was created on 2026-04-20 for Microdex UG and currently originates one /24. No reliable current evidence found ties Microdex to the prior operation; historical reputation is not portable across reassignment.","Analyst Notes":"Retain hosting-origin context if useful, but remove any label asserting current bulletproof behavior until current-holder evidence emerges.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS215764","ASN Number":"215764","Network Name":"V4GUARD Ismael Munoz Hernandez","Aliases":"Ismael Munoz Hernandez","Provider Family":"as215764.net","RIR Country Code":"ES","Country Name":"Spain","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"11.85","ipapi Rank":"996","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #996 with 11.85% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS216067","ASN Number":"216067","Network Name":"AS216067 BHS Solutions GmbH","Aliases":"BHS Solutions GmbH","Provider Family":"bhs.solutions","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.77","ipapi Rank":"696","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #696 with 19.77% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS263833","ASN Number":"263833","Network Name":"AS263833 - DIGITAL SAVIO S.A.","Aliases":"DIGITAL SAVIO S.A.","Provider Family":"","RIR Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.77","ipapi Rank":"746","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #746 with 17.77% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS266187","ASN Number":"266187","Network Name":"AS266187 - LUIZ ANTONIO MARTINS RAMOS JUNIOR 38443782862","Aliases":"LUIZ ANTONIO MARTINS RAMOS JUNIOR 3","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.75","ipapi Rank":"722","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #722 with 18.75% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS270764","ASN Number":"270764","Network Name":"AS270764 - Ecxon Datacenter LTDA","Aliases":"Ecxon Datacenter LTDA","Provider Family":"ecxon.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.16","ipapi Rank":"731","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #731 with 18.16% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"BR:2"},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS271437","ASN Number":"271437","Network Name":"AS271437 - JMV Technology Eireli - EPP","Aliases":"JMV Technology Eireli - EPP","Provider Family":"jmvtechnology.com","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"20","ipapi Rank":"690","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #690 with 20% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS329225","ASN Number":"329225","Network Name":"Lexistar Alliance Ltd. - Lexistar Alliance Ltd.","Aliases":"Lexistar Alliance Ltd.","Provider Family":"lexistream.net","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"afrinic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.76","ipapi Rank":"799","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #799 with 15.76% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS397081","ASN Number":"397081","Network Name":"VALKYRIE-HOSTING - Valkyrie Hosting LLC","Aliases":"Valkyrie Hosting LLC","Provider Family":"valkyrie-hosting.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S02, S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #919 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS397273","ASN Number":"397273","Network Name":"RENDER - Render","Aliases":"Render","Provider Family":"render.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"11.91","ipapi Rank":"992","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #992 with 11.91% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS399935","ASN Number":"399935","Network Name":"HAYASHIMO - Hayashimo LLC","Aliases":"Hayashimo LLC","Provider Family":"hayashimo.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.45","ipapi Rank":"849","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #849 with 14.45% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS400882","ASN Number":"400882","Network Name":"AS-CYBER-DATA - Cyber Data LLC","Aliases":"Cyber Data LLC","Provider Family":"cyberdatanetworks.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.23","ipapi Rank":"813","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #813 with 15.23% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS402186","ASN Number":"402186","Network Name":"SERO - SeroWeb LLC","Aliases":"SeroWeb LLC","Provider Family":"seroweb.xyz","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"High abuse-concentration hosting","Evidence Level":"Medium","FP Risk":"High","Recommended Use":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.06","ipapi Rank":"872","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S02, S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #872 with 14.06% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Abuse concentration is a prioritization metric, not the probability that any specific sign-in is malicious.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS6060","ASN Number":"6060","Network Name":"MAGI-NET-GW - Management Alliance Group Inc.","Aliases":"Management Alliance Group; MAGI-NET-GW; management-alliance-group","Provider Family":"management-alliance-group","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2023-01-19","Network Type":"Dormant legacy network / potentially hijackable ASN","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"Strong","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"208","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS6060 is currently unannounced but remains in the live Spamhaus ASN-DROP feed. Spamhaus specifically covers hijacked or revived dormant ASNs and re-evaluates listings daily. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as MAGI-NET-GW (management-alliance-group).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. No legitimate live route is expected; use the dynamic feed and trigger on any new announcement. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS7411","ASN Number":"7411","Network Name":"WINTERSTORM - StormNet Communications","Aliases":"StormNet Communications; sulharai.com; WINTERSTORM","Provider Family":"sulharai.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2023-06-13","Network Type":"Dormant legacy ISP/hosting network","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"Strong","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"212","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS7411 is unannounced in current routing data and is present in live Spamhaus ASN-DROP, consistent with DROP's coverage of hijacked/revived dormant resources. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as WINTERSTORM (sulharai.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Treat a new route or sign-in mapping as critical, but remove automatically if Spamhaus delists after legitimate reassignment. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS7907","ASN Number":"7907","Network Name":"NETWORD-CORP - Networldtron Corp","Aliases":"Networldtron; networldtron.net; NETWORD-CORP","Provider Family":"networldtron.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2025-05-21","Network Type":"Dormant legacy ISP/hosting network","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"Strong","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"214","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS7907 is unannounced in current routing data and is present in live Spamhaus ASN-DROP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NETWORD-CORP (networldtron.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current dynamic DROP status is stronger than stale nominal-registration data. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS8075","ASN Number":"8075","Network Name":"MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation","Aliases":"MICROSOFT-CORP-MSN-AS-BLOCK; Azure; microsoft.com; Microsoft Corporation","Provider Family":"Microsoft","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hyperscale cloud / first-party services","Category":"Broad Microsoft cloud / first-party false-positive risk","Evidence Level":"Context only","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"S05, X065, X066, N01","Evidence Summary":"Microsoft owns AS8075. Exclude it from ASN-only identity alerts because first-party services, integrations and Microsoft-hosted workloads can originate there. AS8075 is Microsoft's global network and carries Azure and Microsoft online services. It is not in current Spamhaus ASN-DROP. ASN-only matching would create severe false positives in a Microsoft 365 environment and can also match tenant-to-tenant or platform traffic.","Analyst Notes":"Do not treat AS8075 as a malicious-network label. If retained, require interactive sign-in plus strong identity, device, and session anomalies.","Current Community Feed Count":"3","Current Listed IPs":"7219","IPsum IPs":"3914","IPsum Score >=3":"1562","IPsum Score >=5":"155","Open-Proxy IPs":"191","Data-Shield IPs":"5622","Talos 2024 IPs":"0","Multi-list IPs":"2508","Listed-IP Country Mix":"US:6231, IN:176, CA:84, HK:71, NL:69, JP:63, KR:54, SG:49"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS12586","ASN Number":"12586","Network Name":"ASGHOSTNET GHOSTnet GmbH","Aliases":"","Provider Family":"GHOSTnet","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Behavior-correlated enrollment infrastructure","Evidence Level":"Direct point IOC","FP Risk":"High","Recommended Use":"Disabled by default. Alert on the exact IP or ASN only when correlated with device-code abuse, scripting user agents, token replay, or unexpected Intune/device enrollment.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes, exact IP and enrollment sequence","Actor / Campaign":"GhostCode","Last Evidence":"2026-09-29","Source IDs":"N48, N01","Evidence Summary":"eSentire observed final Intune enrollment from 5.230.71.51 on reported AS12586 after GhostCode device-code token theft. This is one incident and does not establish provider complicity.","Analyst Notes":"Current origin was revalidated on 2026-09-29. Keep exact-IP and behavior correlation primary.","Current Community Feed Count":"1","Current Listed IPs":"10","IPsum IPs":"10","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"DE:10"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS13317","ASN Number":"13317","Network Name":"AS-WAN - Wan holdings LLC","Aliases":"Wan holdings LLC","Provider Family":"","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"23.05","ipapi Rank":"649","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #649 with 23.05% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS13332","ASN Number":"13332","Network Name":"HYPEENT-SJ - Hype Enterprises","Aliases":"Hype Enterprises","Provider Family":"hypecreation.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"11.85","ipapi Rank":"997","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #997 with 11.85% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"545","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"544","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"US:521, JP:24"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS13335","ASN Number":"13335","Network Name":"CLOUDFLARENET - Cloudflare, Inc.","Aliases":"","Provider Family":"Cloudflare","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Broad cloud/CDN control row","Evidence Level":"Context","FP Risk":"Very High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"ARToken / EvilTokens phishing infrastructure behind Cloudflare","Last Evidence":"2026-07-01","Source IDs":"N20, N01","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"5753","IPsum IPs":"166","IPsum Score >=3":"8","IPsum Score >=5":"2","Open-Proxy IPs":"5475","Data-Shield IPs":"241","Talos 2024 IPs":"0","Multi-list IPs":"129","Listed-IP Country Mix":"CA:4148, GB:760, US:369, PL:278, CR:45, IE:27, CL:25, DE:16"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS13926","ASN Number":"13926","Network Name":"NETPROTECT-PHX - Strong Technology, LLC.","Aliases":"","Provider Family":"Strong Technology / NetProtect","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"United States","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Commercial VPN / hosting / proxy","Category":"Commercial VPN provider family expansion","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"StrongVPN / Strong Technology family","Last Evidence":"2026-09-15","Source IDs":"N35, N36, N01","Evidence Summary":"Active Strong Technology / NetProtect family ASN without sufficient direct campaign-time evidence for automatic monitoring. Disabled pending local need and validation.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"0","Current Listed IPs":"8","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"8","Multi-list IPs":"0","Listed-IP Country Mix":"US:8"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS14618","ASN Number":"14618","Network Name":"AMAZON-AES - Amazon.com, Inc.","Aliases":"","Provider Family":"Amazon Web Services","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Broad cloud/CDN control row","Evidence Level":"Context","FP Risk":"Very High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N01","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"2313","IPsum IPs":"1866","IPsum Score >=3":"349","IPsum Score >=5":"12","Open-Proxy IPs":"115","Data-Shield IPs":"1215","Talos 2024 IPs":"0","Multi-list IPs":"883","Listed-IP Country Mix":"US:2312, CA:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS15012","ASN Number":"15012","Network Name":"TRIOLAB - NextStage Innovations LLC","Aliases":"NextStage Innovations LLC","Provider Family":"nextstageinnovations.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"25.78","ipapi Rank":"613","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #613 with 25.78% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS15169","ASN Number":"15169","Network Name":"GOOGLE - Google LLC","Aliases":"","Provider Family":"Google","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Broad cloud/CDN control row","Evidence Level":"Context","FP Risk":"Very High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N01","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"48","IPsum IPs":"33","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"14","Data-Shield IPs":"15","Talos 2024 IPs":"0","Multi-list IPs":"14","Listed-IP Country Mix":"IN:19, US:11, IT:4, SG:3, AU:2, BR:2, JP:2, TW:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS16276","ASN Number":"16276","Network Name":"OVH OVH SAS","Aliases":"","Provider Family":"OVHcloud","RIR Country Code":"FR","Country Name":"France","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Large shared cloud / VPS","Category":"Broad cloud provider with exact historical IOCs","Evidence Level":"High for exact IPs; weak for ASN-wide use","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"Proofpoint 2022 cloud credential attacks","Last Evidence":"2022-03-03","Source IDs":"S04, S06, N01","Evidence Summary":"Two exact Proofpoint login-source IOCs historically originated from AS16276. OVH is a large shared cloud; keep the IP history but disable whole-ASN alerts by default.","Analyst Notes":"","Current Community Feed Count":"3","Current Listed IPs":"3297","IPsum IPs":"2426","IPsum Score >=3":"98","IPsum Score >=5":"34","Open-Proxy IPs":"332","Data-Shield IPs":"1010","Talos 2024 IPs":"6","Multi-list IPs":"475","Listed-IP Country Mix":"FR:1080, GB:725, CA:431, US:289, DE:264, PL:165, SG:82, NL:46"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS16509","ASN Number":"16509","Network Name":"AMAZON-02 - Amazon.com, Inc.","Aliases":"","Provider Family":"Amazon Web Services","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Broad cloud/CDN control row","Evidence Level":"Context","FP Risk":"Very High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N01","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"2039","IPsum IPs":"1173","IPsum Score >=3":"8","IPsum Score >=5":"2","Open-Proxy IPs":"477","Data-Shield IPs":"549","Talos 2024 IPs":"9","Multi-list IPs":"169","Listed-IP Country Mix":"US:846, SG:388, IN:99, JP:88, IE:78, DE:76, SE:54, CA:45"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS16625","ASN Number":"16625","Network Name":"AKAMAI-AS - Akamai Technologies, Inc.","Aliases":"","Provider Family":"Akamai","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Broad cloud/CDN control row","Evidence Level":"Context","FP Risk":"Very High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N01","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"1","Current Listed IPs":"2","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"2","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"US:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS17447","ASN Number":"17447","Network Name":"NET4-IN - Net4India Ltd","Aliases":"Net4India; net4india.com; NET4-IN","Provider Family":"net4india.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-06-14","Network Type":"Dormant legacy ISP/hosting network","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"Strong","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"219","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS17447 is unannounced in current routing data and remains in live Spamhaus ASN-DROP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NET4-IN (net4india.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. No normal current login source is expected; refresh dynamically to catch delisting or reassignment. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS17994","ASN Number":"17994","Network Name":"SPARK-AS-AP - Spark New Zealand Trading Ltd","Aliases":"AppServ; appserv.co.nz; Spark New Zealand (nominal legacy holder); SPARK-AS-AP; Spark New Zealand Trading Limited","Provider Family":"appserv.co.nz","RIR Country Code":"NZ","Country Name":"New Zealand","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-05-19","Network Type":"Dormant legacy hosting/services ASN","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"Strong","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"221","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"This specific, currently unannounced ASN is in live Spamhaus ASN-DROP under appserv.co.nz. This finding does not apply to Spark New Zealand's other production ASNs. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SPARK-AS-AP (appserv.co.nz).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Scope the rule to AS17994 only; do not generalize the label to Spark's broader network. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS20940","ASN Number":"20940","Network Name":"AKAMAI-ASN1 Akamai International B.V.","Aliases":"","Provider Family":"Akamai","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Broad cloud/CDN control row","Evidence Level":"Context","FP Risk":"Very High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N01","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"1","Current Listed IPs":"6","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"6","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"US:4, DE:1, JP:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS21308","ASN Number":"21308","Network Name":"ITMUA-AS Synapse Ukraine LLC","Aliases":"Synapse Ukraine LLC","Provider Family":"synapse.net.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.7","ipapi Rank":"949","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #949 with 12.7% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS22781","ASN Number":"22781","Network Name":"STRTEC - Strong Technology, LLC.","Aliases":"","Provider Family":"Strong Technology / NetProtect","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"United States","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Commercial VPN / hosting / proxy","Category":"Commercial VPN provider family expansion","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"StrongVPN / Strong Technology family","Last Evidence":"2026-09-15","Source IDs":"N35, N36, N01","Evidence Summary":"Active Strong Technology / NetProtect family ASN without sufficient direct campaign-time evidence for automatic monitoring. Disabled pending local need and validation.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"1","Current Listed IPs":"27","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"26","Multi-list IPs":"0","Listed-IP Country Mix":"US:26, LU:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS24426","ASN Number":"24426","Network Name":"CNNIC-SINO-I - Beijing CE Huatong Information Technology Co., Ltd.","Aliases":"Beijing CE Huatong; myce.net.cn; CNNIC-SINO-I","Provider Family":"myce.net.cn","RIR Country Code":"CN","Country Name":"China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-02-05","Network Type":"Dormant legacy hosting/internet-services ASN","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"Strong","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"223","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS24426 is currently unannounced and present in live Spamhaus ASN-DROP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CNNIC-SINO-I (myce.net.cn).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Block only through a refreshed feed and alert on reannouncement. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS24567","ASN Number":"24567","Network Name":"QTINC-AS-AP - QT Inc.","Aliases":"QT Cloud; qtcloud.co.jp; QTINC-AS-AP","Provider Family":"qtcloud.co.jp","RIR Country Code":"JP","Country Name":"Japan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2024-09-02","Network Type":"Dormant legacy cloud/hosting ASN","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"Strong","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"224","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS24567 is currently unannounced and present in live Spamhaus ASN-DROP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as QTINC-AS-AP (qtcloud.co.jp).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. A current route would be unexpected; automatically honor future delisting. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS25099","ASN Number":"25099","Network Name":"AS25099 PE NEO-CRAFT","Aliases":"PE NEO-CRAFT","Provider Family":"mozmail.com","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.45","ipapi Rank":"856","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #856 with 14.45% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"UA:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS25133","ASN Number":"25133","Network Name":"MCLAUT-AS LLC \"McLaut-Invest\"","Aliases":"LLC McLaut-Invest","Provider Family":"mclaut.com","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.34","ipapi Rank":"964","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #964 with 12.34% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"35","IPsum IPs":"20","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"27","Talos 2024 IPs":"0","Multi-list IPs":"12","Listed-IP Country Mix":"UA:35"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS25820","ASN Number":"25820","Network Name":"IT7NET - IT7 Networks Inc","Aliases":"","Provider Family":"IT7 Networks Inc","RIR Country Code":"CA","Country Name":"Canada","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Point-IOC provider context","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Exact-IP context","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"N39, N01","Evidence Summary":"Current origin of Kapibala C2 104.225.153.141. This supports source-scoped review, not provider-wide malicious attribution.","Analyst Notes":"Do not enable from this source alone.","Current Community Feed Count":"3","Current Listed IPs":"24","IPsum IPs":"8","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"15","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"US:20, NL:2, CA:1, JP:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS26561","ASN Number":"26561","Network Name":"NETRIDGE - NetRidge LLC","Aliases":"NetRidge; mylir.co.uk; NETRIDGE; NetRidge LLC","Provider Family":"mylir.co.uk","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2026-08-06","Network Type":"Dormant legacy hosting ASN","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"Strong","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"228","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS26561 is currently unannounced and present in live Spamhaus ASN-DROP under mylir.co.uk. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NETRIDGE (mylir.co.uk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use live feed state, not the stale nominal organization name. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS27463","ASN Number":"27463","Network Name":"AS-GLOBALTELEHOST - GLOBALTELEHOST Corp.","Aliases":"GLOBALTELEHOST Corp.; AS-GLOBALTELEHOST","Provider Family":"globaltelehost.com","RIR Country Code":"CA","Country Name":"Canada","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2026-01-07","Network Type":"Hosting / VPS / proxy","Category":"Former ASN-DROP; non-originating lifecycle review","Evidence Level":"Historical / lifecycle","FP Risk":"Very High","Recommended Use":"Disabled by default. Retain history and review current assignment, origin, and exact indicators before any enforcement.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01","Evidence Summary":"Present in the 2026-09-15 ASN-DROP snapshot and absent from the 2026-09-29 snapshot; delisting does not establish benignness.","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current RIR and routing state require lifecycle review.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS27712","ASN Number":"27712","Network Name":"AS27712 - Paulo Dias de Araujo Filho","Aliases":"Paulo Dias de Araujo Filho","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17","ipapi Rank":"766","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #766 with 17% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS28111","ASN Number":"28111","Network Name":"AS28111 - Grupo Solunet SRL","Aliases":"Grupo Solunet SRL","Provider Family":"solunet.com.ar","RIR Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.03","ipapi Rank":"795","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #795 with 16.03% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"3","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"AR:3"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS29182","ASN Number":"29182","Network Name":"RU-JSCIOT JSC IOT","Aliases":"","Provider Family":"","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Unknown / review","Category":"Historical single-IP actor infrastructure","Evidence Level":"High for exact IP; weak for ASN-wide use","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"Gamaredon / Primitive Bear","Last Evidence":"2022-02-03","Source IDs":"S08, N01","Evidence Summary":"One short-lived Gamaredon C2 resolution was reported in this ASN. Preserve the exact IP only; do not enable ASN-wide monitoring without local evidence.","Analyst Notes":"","Current Community Feed Count":"3","Current Listed IPs":"106","IPsum IPs":"61","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"39","Data-Shield IPs":"12","Talos 2024 IPs":"0","Multi-list IPs":"6","Listed-IP Country Mix":"RU:106"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS29233","ASN Number":"29233","Network Name":"IIP-NET-AS29233 Telecommunications center UMOS, LLC","Aliases":"Telecommunications center UMOS, LLC","Provider Family":"umos.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.09","ipapi Rank":"918","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #918 with 13.09% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS30490","ASN Number":"30490","Network Name":"ETHRN - Ethr.Net LLC","Aliases":"Ethr.Net; ethr.net; ETHRN","Provider Family":"ethr.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2018-01-25","Network Type":"Dormant internet-infrastructure ASN","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"Strong","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"230","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS30490 is currently unannounced and present in live Spamhaus ASN-DROP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ETHRN (ethr.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. No ordinary live source is expected; dynamic refresh limits reassignment risk. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS30823","ASN Number":"30823","Network Name":"AUROLOGIC aurologic GmbH","Aliases":"combahton GmbH; fastpipe.io; aurologic; aurologic GmbH","Provider Family":"combahton GmbH","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Transit / upstream carrier context only","Category":"Legitimate upstream carrier, context only","Evidence Level":"High","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"upstream transit for multiple high-risk and malicious networks","Last Evidence":"2025-11-06","Source IDs":"S05, X003, X031, N01","Evidence Summary":"Recorded Future found aurologic to be a central upstream providing connectivity to many high-risk networks. The report expressly frames it as a legitimate carrier and does not establish aurologic itself as criminal or bulletproof hosting. Recorded Future's 2025 investigation identifies AS30823 as a central upstream and hosting nexus for multiple high-risk networks and suspected threat-activity enablers, including sanctioned Aeza infrastructure. The report expressly leaves negligence-versus-complicity unresolved and notes legitimate hosting/transit operations.","Analyst Notes":"High-risk downstream concentration makes AS30823 useful context for identity detections, but its substantial transit role creates collateral risk from blanket blocking. High for topology and transit role; insufficient for provider-level maliciousness. This row is a deliberate no-block/context control. Active and announcing routes as aurologic GmbH on 2026-09-15. CONTEXT ONLY-do not put the whole ASN in an identity deny list.","Current Community Feed Count":"3","Current Listed IPs":"22","IPsum IPs":"18","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"4","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"DE:19, US:3"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS31345","ASN Number":"31345","Network Name":"MAGISTRAL2-AS Business Network Ltd","Aliases":"Business Network Ltd","Provider Family":"bn.by","RIR Country Code":"BY","Country Name":"Belarus","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.48","ipapi Rank":"753","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #753 with 17.48% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS31898","ASN Number":"31898","Network Name":"ORACLE-BMC-31898 - Oracle Corporation","Aliases":"","Provider Family":"Oracle Cloud","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Broad cloud/CDN control row","Evidence Level":"Context","FP Risk":"Very High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N01","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"1454","IPsum IPs":"704","IPsum Score >=3":"109","IPsum Score >=5":"57","Open-Proxy IPs":"292","Data-Shield IPs":"840","Talos 2024 IPs":"0","Multi-list IPs":"381","Listed-IP Country Mix":"US:382, SG:340, BR:140, JP:109, IN:98, DE:72, KR:70, AE:44"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS33847","ASN Number":"33847","Network Name":"AE-ANKABUT Khalifa University","Aliases":"Khalifa University","Provider Family":"ku.ac.ae","RIR Country Code":"AE","Country Name":"United Arab Emirates","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Education","Category":"High-abuse education review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.63","ipapi Rank":"803","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this education ASN #803 with 15.63% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS33923","ASN Number":"33923","Network Name":"ART-COM ART-COM Sp. z o.o.","Aliases":"ART-COM Sp. z o.o.","Provider Family":"artcom.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the Very High band at rank #571 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS33991","ASN Number":"33991","Network Name":"IGRA-SERVICE-AS IGRA-SERVICE LLC","Aliases":"IGRA-SERVICE LLC","Provider Family":"g-service.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"11.92","ipapi Rank":"989","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #989 with 11.92% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"4","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RU:4"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS34142","ASN Number":"34142","Network Name":"BARTA-AS LLC \"MicroTeam\"","Aliases":"LLC MicroTeam","Provider Family":"","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.06","ipapi Rank":"873","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #873 with 14.06% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS34515","ASN Number":"34515","Network Name":"NextNet-AS Next Net for Internet and IT Services LTD","Aliases":"Next Net for Internet and IT Services LT","Provider Family":"nextnet.co","RIR Country Code":"IQ","Country Name":"Iraq","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"25.49","ipapi Rank":"616","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #616 with 25.49% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"IQ:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS34582","ASN Number":"34582","Network Name":"VORONEZHSIGNAL-AS Voronezh-Signal LLC","Aliases":"Voronezh-Signal LLC","Provider Family":"vsignal.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.5","ipapi Rank":"953","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #953 with 12.5% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS35695","ASN Number":"35695","Network Name":"FALCON-AS F-NET sp. z o.o.","Aliases":"F-NET sp. z o.o.","Provider Family":"f-net.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.43","ipapi Rank":"810","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #810 with 15.43% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS36849","ASN Number":"36849","Network Name":"SAEOL-1-ASN - 1st Amendment Encrypted Openness LLC","Aliases":"1st Amendment Encrypted Openness LLC","Provider Family":"1aeo.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"98.29","ipapi Rank":"466","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #466 with 98.29% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1003","IPsum IPs":"1003","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"US:943, NL:60"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS38337","ASN Number":"38337","Network Name":"CNNIC-NTNet - NIU Telecommunications Inc","Aliases":"CNNIC-NTNet; niutelecom.com; NIU Telecommunications Inc","Provider Family":"niutelecom.com","RIR Country Code":"CN","Country Name":"China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2023-06-14","Network Type":"telecommunications network (currently unannounced)","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"high","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"235","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CNNIC-NTNet (niutelecom.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS39297","ASN Number":"39297","Network Name":"ARTEFACT Prikarpatinserv LLC","Aliases":"Prikarpatinserv LLC","Provider Family":"arte-fact.net","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.06","ipapi Rank":"874","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #874 with 14.06% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"3","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"UA:3"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS39361","ASN Number":"39361","Network Name":"YARCOM-AS Yarcom LLC","Aliases":"Yarcom LLC","Provider Family":"","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.06","ipapi Rank":"864","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #864 with 14.06% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"UA:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS39577","ASN Number":"39577","Network Name":"GOODNET-AS Goodnet LLC","Aliases":"Goodnet LLC","Provider Family":"gdnet.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"23.58","ipapi Rank":"644","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #644 with 23.58% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RU:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS39690","ASN Number":"39690","Network Name":"OPSFOX-CLOUD DIGITAL NETWORK S.R.L.","Aliases":"Digital-Network; DigitalOcean, LLC; DIGITAL NETWORK S.R.L.","Provider Family":"","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"hosting network (currently unannounced)","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"low","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"S05, N01","Evidence Summary":"Current registry metadata assigns AS39690 to DIGITAL NETWORK S.R.L., but RIPEstat shows it is not announced. It is absent from the 2026-09-15 Spamhaus ASN-DROP snapshot, and no credible source-confirmed bulletproof-hosting or current campaign evidence was located.","Analyst Notes":"Retain only as historical context. A dormant generic-hosting ASN is not an actionable login source today, and a static ASN rule could mislabel a future reassignee. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS39720","ASN Number":"39720","Network Name":"MANILICH-AS Manilich Alla Valerievna","Aliases":"MANILICH-AS; darkclub.com.ua; Manilich Alla Valerievna","Provider Family":"darkclub.com.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2020-12-05","Network Type":"hosting / access network (currently unannounced)","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"high","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"238","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as MANILICH-AS (darkclub.com.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS39798","ASN Number":"39798","Network Name":"MivoCloud MivoCloud SRL","Aliases":"","Provider Family":"","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Historical single-IP actor infrastructure","Evidence Level":"High for exact IP; weak for ASN-wide use","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"Gamaredon / Primitive Bear","Last Evidence":"2022-02-03","Source IDs":"S08, N01","Evidence Summary":"One short-lived Gamaredon C2 resolution was reported in this ASN. Preserve the exact IP only; do not enable ASN-wide monitoring without local evidence.","Analyst Notes":"","Current Community Feed Count":"2","Current Listed IPs":"19","IPsum IPs":"18","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"MD:12, RO:6, US:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS40665","ASN Number":"40665","Network Name":"SPCTR - SPECTRE NETWORKS LTD","Aliases":"SPCTR; spectrenetworks.net; SPECTRE NETWORKS LTD","Provider Family":"spectrenetworks.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2019-11-09","Network Type":"hosting / network services (currently unannounced)","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"high","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"239","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SPCTR (spectrenetworks.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS40963","ASN Number":"40963","Network Name":"PRAID-AS DEMENIN B.V.","Aliases":"PRAID-AS; bignet.ua; DEMENIN B.V.","Provider Family":"bignet.ua","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-05-02","Network Type":"hosting / transit network (currently unannounced)","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"high","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"240","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as PRAID-AS (bignet.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS41171","ASN Number":"41171","Network Name":"Synergynet DIGITAL NETWORK S.R.L.","Aliases":"Synergynet; DIGITAL NETWORK S.R.L.","Provider Family":"","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-07-02","Network Type":"hosting network (currently unannounced)","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"low","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"S05, N01","Evidence Summary":"Current registry metadata assigns AS41171 to DIGITAL NETWORK S.R.L. under the Synergynet name, but RIPEstat shows no announcement. It is absent from the current Spamhaus ASN-DROP snapshot; no credible source-confirmed BPH or recent campaign association was located.","Analyst Notes":"Archive and re-check only if the ASN resumes routing. Do not treat a dormant hosting registration as a current malicious source. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS41297","ASN Number":"41297","Network Name":"ABAKS-AS Adam Dlugosz trading as ABAKS","Aliases":"Adam Dlugosz trading as ABAKS","Provider Family":"abaks.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"47.38","ipapi Rank":"526","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #526 with 47.38% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS41302","ASN Number":"41302","Network Name":"MART-AS KVS Ltd","Aliases":"KVS Ltd","Provider Family":"mart.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.68","ipapi Rank":"952","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #952 with 12.68% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RU:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS42192","ASN Number":"42192","Network Name":"India THUNDER NETWORK LIMITED","Aliases":"India; idodns.com; THUNDER NETWORK LIMITED","Provider Family":"idodns.com","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-05-13","Network Type":"hosting / DNS network (currently unannounced)","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"high","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"241","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as India (idodns.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS42216","ASN Number":"42216","Network Name":"Netviser Bilisim Teknolojileri San. Ve T","Aliases":"","Provider Family":"internetsahibi.net","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Current abuse-concentration hosting review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.3","ipapi Rank":"702","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #702 with 19.3% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Vendor concentration is a prioritization signal, not malicious-login probability or provider complicity.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS42419","ASN Number":"42419","Network Name":"TAVRIA-TRANSSERVIS-AS Tavria-TRANSSERVIS Ltd","Aliases":"TAVRIA-TRANSSERVIS-AS; tavriatrans.com.ua; Tavria-TRANSSERVIS Ltd","Provider Family":"tavriatrans.com.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2021-05-07","Network Type":"enterprise / transport-company network (currently unannounced)","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"high","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"242","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as TAVRIA-TRANSSERVIS-AS (tavriatrans.com.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS42694","ASN Number":"42694","Network Name":"CONTRUST Elektrizitaetswerk Goesting V. Franz GmbH","Aliases":"CONTRUST; CYGATEGROUP-MALMO (historical); Avinova AB (historical); Elektrizitaetswerk Goesting V. Franz GmbH","Provider Family":"","RIR Country Code":"AT","Country Name":"Austria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-05-19","Network Type":"utility / enterprise network (currently unannounced)","Category":"Allocated but long-unannounced manual-review candidate","Evidence Level":"low","FP Risk":"N/A","Recommended Use":"Disabled pending fresh route visibility and current holder validation.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"S05, X029, N01","Evidence Summary":"Current RIPEstat metadata assigns AS42694 to the Austrian utility Elektrizitaetswerk Goesting V. Franz GmbH under CONTRUST and shows it unannounced. Older public ASN data recorded CYGATEGROUP-MALMO / Avinova AB, confirming identity churn. It is absent from current ASN-DROP, and no credible current abuse evidence was located.","Analyst Notes":"The current holder is materially different from the historical identity. Remove from active malicious-ASN logic; revalidate ownership and routes before any future use. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.; Long-unannounced allocated ASN; absence as an origin alone is not proof of retirement.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS42881","ASN Number":"42881","Network Name":"Kontrast Contrust Solutions S.R.L.","Aliases":"Kontrast; kontrast.md; Contrust Solutions S.R.L.","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-03-31","Network Type":"IT / hosting network (currently unannounced)","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"high","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"244","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Kontrast (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS42969","ASN Number":"42969","Network Name":"ALPHASTRIKE Alpha Strike Labs GmbH","Aliases":"Alpha Strike Labs GmbH","Provider Family":"alphastrike.io","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"66.15","ipapi Rank":"484","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #484 with 66.15% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"508","IPsum IPs":"487","IPsum Score >=3":"17","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"254","Talos 2024 IPs":"0","Multi-list IPs":"233","Listed-IP Country Mix":"US:508"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS43049","ASN Number":"43049","Network Name":"MULTISYSTEM-AS Multisystem Technologies Ltd.","Aliases":"Multisystem Technologies Ltd.","Provider Family":"multisystem.net.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.65","ipapi Rank":"842","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #842 with 14.65% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"7","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"7","Talos 2024 IPs":"0","Multi-list IPs":"3","Listed-IP Country Mix":"UA:7"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS43094","ASN Number":"43094","Network Name":"Digital-Network DIGITAL NETWORK S.R.L.","Aliases":"Digital-Network; DIGITAL NETWORK S.R.L.","Provider Family":"","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"hosting network (currently unannounced)","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"low","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"S05, X033, N01","Evidence Summary":"Current registry metadata assigns AS43094 to DIGITAL NETWORK S.R.L., while RIPEstat shows no route announcement. It is absent from current ASN-DROP. Public network directories classify the historic footprint as hosting/data-center space, but that is a business-type label, not evidence of malicious operation.","Analyst Notes":"Archive as inactive generic hosting. If it returns, evaluate current prefixes and recent threat telemetry rather than inheriting the old-list label. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS43273","ASN Number":"43273","Network Name":"OPTIKLINE-AS Optik Line LLC","Aliases":"Optik Line LLC","Provider Family":"optikline.com","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"20.34","ipapi Rank":"682","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #682 with 20.34% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS43420","ASN Number":"43420","Network Name":"ELTRONIK-AS Eltronik Sp. z o.o.","Aliases":"Eltronik Sp. z o.o.","Provider Family":"eltronik.net.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"25.26","ipapi Rank":"621","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #621 with 25.26% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS43530","ASN Number":"43530","Network Name":"IRTELCOM-AS Limited Liability Company Irtelcom","Aliases":"Limited Liability Company Irtelcom","Provider Family":"irtelcom.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.06","ipapi Rank":"765","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #765 with 17.06% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"2","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RU:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS43613","ASN Number":"43613","Network Name":"SOWA LLC BIGNET UKRAINE","Aliases":"SOWA; liptel.net.ua; BIGNET UKRAINE","Provider Family":"liptel.net.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-05-13","Network Type":"telecommunications network (currently unannounced)","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"high","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"246","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SOWA (liptel.net.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS43764","ASN Number":"43764","Network Name":"SEVLUSH-AS LLC \"Electron-sevlush\"","Aliases":"LLC Electron-sevlush","Provider Family":"sevlush.net","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"23.64","ipapi Rank":"642","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #642 with 23.64% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"11","IPsum IPs":"5","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"8","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"UA:11"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS43822","ASN Number":"43822","Network Name":"HOMEOPTIC HOMEOPTIC LLC","Aliases":"HOMEOPTIC LLC","Provider Family":"homeoptic.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.87","ipapi Rank":"884","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #884 with 13.87% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS43830","ASN Number":"43830","Network Name":"DIGITALENERGY-AS Basis LLC","Aliases":"","Provider Family":"","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Unknown / review","Category":"Historical single-IP actor infrastructure","Evidence Level":"High for exact IP; weak for ASN-wide use","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"Gamaredon / Primitive Bear","Last Evidence":"2022-02-03","Source IDs":"S08, N01","Evidence Summary":"One short-lived Gamaredon C2 resolution was reported in this ASN. Preserve the exact IP only; do not enable ASN-wide monitoring without local evidence.","Analyst Notes":"","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS44541","ASN Number":"44541","Network Name":"PRELUTION-AS Jochem Stobbe trading as Prelution","Aliases":"Jochem Stobbe trading as Prelution","Provider Family":"prelution.nl","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"48.83","ipapi Rank":"524","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #524 with 48.83% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS44589","ASN Number":"44589","Network Name":"NTservers DIGITAL NETWORK S.R.L.","Aliases":"Digital-Network; Hosting; DIGITAL NETWORK S.R.L.","Provider Family":"","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"hosting network (currently unannounced)","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"low","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.67","ipapi Rank":"891","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S05, X039, N01, S03","Evidence Summary":"Current registry metadata assigns AS44589 to DIGITAL NETWORK S.R.L. and RIPEstat shows it unannounced. BGP.Tools likewise describes a network with no peers or upstreams. It is absent from the current Spamhaus ASN-DROP snapshot, and no source-confirmed BPH or current campaign evidence was located.","Analyst Notes":"Archive as inactive hosting metadata. Do not turn an old-list entry into an ASN-wide risk assertion without new route and abuse evidence. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS44678","ASN Number":"44678","Network Name":"TVT-NET INKO Ltd.","Aliases":"INKO Ltd.","Provider Family":"tvtk.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.64","ipapi Rank":"777","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #777 with 16.64% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS44801","ASN Number":"44801","Network Name":"R-TEL-AS \"R-TEL\" LLC","Aliases":"R-TEL-AS; bignet.ua; R-TEL LLC","Provider Family":"bignet.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-05-02","Network Type":"telecommunications / hosting network (currently unannounced)","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"high","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"248","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as R-TEL-AS (bignet.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS44834","ASN Number":"44834","Network Name":"POZITIVTELECOM-AS LLC \"POZITIV TELEKOM\"","Aliases":"LLC POZITIV TELEKOM","Provider Family":"pozitivtelecom.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.89","ipapi Rank":"932","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #932 with 12.89% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS45102","ASN Number":"45102","Network Name":"ALIBABA-CN-NET - Alibaba (US) Technology Co., Ltd.","Aliases":"","Provider Family":"Alibaba Cloud","RIR Country Code":"CN","Country Name":"China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Broad cloud/CDN control row","Evidence Level":"Context","FP Risk":"Very High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N01","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"5236","IPsum IPs":"4346","IPsum Score >=3":"601","IPsum Score >=5":"11","Open-Proxy IPs":"524","Data-Shield IPs":"3394","Talos 2024 IPs":"0","Multi-list IPs":"3025","Listed-IP Country Mix":"SG:1733, US:1041, JP:684, HK:586, MY:508, DE:506, KR:69, ID:36"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS47105","ASN Number":"47105","Network Name":"as-vd Vault Dweller OU","Aliases":"as-vd; vaultdweller.net; Vault Dweller OU","Provider Family":"vaultdweller.net","RIR Country Code":"EE","Country Name":"Estonia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-06-26","Network Type":"hosting / network services (currently unannounced)","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"high","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"249","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as as-vd (vaultdweller.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Use as an urgent authentication-risk signal or deny source where business policy permits, and refresh from ASN-DROP daily. Do not infer actor nationality from the registry or feed country. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS47154","ASN Number":"47154","Network Name":"HUSAM-Network HUSAM A. H. HIJAZI","Aliases":"HUSAM A. H. HIJAZI","Provider Family":"as49870.net","RIR Country Code":"PS","Country Name":"Palestinian Territories","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"62.5","ipapi Rank":"487","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #487 with 62.5% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"256","IPsum IPs":"256","IPsum Score >=3":"20","IPsum Score >=5":"3","Open-Proxy IPs":"0","Data-Shield IPs":"19","Talos 2024 IPs":"0","Multi-list IPs":"19","Listed-IP Country Mix":"HK:256"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS47204","ASN Number":"47204","Network Name":"MCS-AS MCS LLC","Aliases":"MCS LLC","Provider Family":"mcs.ooo","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"23.93","ipapi Rank":"636","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #636 with 23.93% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS47288","ASN Number":"47288","Network Name":"FIXNET FIXNET Telekomunikasyon Limited Sirketi","Aliases":"FIXNET Telekomunikasyon Limited Sirketi","Provider Family":"fixnet.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"11.89","ipapi Rank":"995","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #995 with 11.89% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS47329","ASN Number":"47329","Network Name":"WDM-AS WDM Sp. z o.o.","Aliases":"WDM Sp. z o.o.","Provider Family":"wdm.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"61.93","ipapi Rank":"488","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #488 with 61.93% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS47397","ASN Number":"47397","Network Name":"BASE-AS Base Ltd.","Aliases":"Base Ltd.","Provider Family":"base-net.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.87","ipapi Rank":"833","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #833 with 14.87% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS47500","ASN Number":"47500","Network Name":"www-networkpolice-org SC ITNS.NET SRL","Aliases":"www-networkpolice-org; ITNS.NET; SC ITNS.NET SRL","Provider Family":"","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-05-19","Network Type":"hosting / network services (currently unannounced)","Category":"Allocated but long-unannounced manual-review candidate","Evidence Level":"low","FP Risk":"N/A","Recommended Use":"Disabled pending fresh route visibility and current holder validation.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"S05, X044, N01","Evidence Summary":"Current registry metadata assigns AS47500 to SC ITNS.NET SRL under www-networkpolice-org, but RIPEstat shows it unannounced. It is absent from current Spamhaus ASN-DROP, and no credible source-confirmed BPH or recent campaign evidence was located.","Analyst Notes":"Treat as inactive historical hosting metadata only. Revalidate the holder, routes and IP-level evidence before restoring any alert or block rule. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.; Long-unannounced allocated ASN; absence as an origin alone is not proof of retirement.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS47551","ASN Number":"47551","Network Name":"AS-MAYAK-NETWORK \"MAYAK NETWORK\" LLC","Aliases":"MAYAK NETWORK LLC","Provider Family":"mayaknet.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.3","ipapi Rank":"967","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #967 with 12.3% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RU:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS47860","ASN Number":"47860","Network Name":"OTC-AS OOO \"OTC\"","Aliases":"OOO OTC","Provider Family":"bsh.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.3","ipapi Rank":"965","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #965 with 12.3% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"RU:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS48120","ASN Number":"48120","Network Name":"FLASHTELECOM-AS Flash Telecom LLC","Aliases":"Flash Telecom LLC","Provider Family":"flash-telecom.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"23.44","ipapi Rank":"645","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #645 with 23.44% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS48162","ASN Number":"48162","Network Name":"VYSHKOVO-AS Bihunets Ishtvan Stepanovych","Aliases":"Bihunets Ishtvan Stepanovych","Provider Family":"","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.36","ipapi Rank":"728","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #728 with 18.36% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS48433","ASN Number":"48433","Network Name":"OMIPLAT-AS Omiplat LLC","Aliases":"Omiplat LLC","Provider Family":"omiplat.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.79","ipapi Rank":"942","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #942 with 12.79% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS48494","ASN Number":"48494","Network Name":"MKNET-AS BUKO LTD","Aliases":"BUKO LTD","Provider Family":"mknet.biz","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.36","ipapi Rank":"758","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #758 with 17.36% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS48525","ASN Number":"48525","Network Name":"UZUMBANK-AS JSC Uzum Bank","Aliases":"JSC Uzum Bank","Provider Family":"uzumbank.uz","RIR Country Code":"UZ","Country Name":"Uzbekistan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Banking","Category":"High-abuse banking review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.14","ipapi Rank":"710","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this banking ASN #710 with 19.14% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS48974","ASN Number":"48974","Network Name":"Digital-Network DIGITAL NETWORK S.R.L.","Aliases":"Digital-Network; DIGITAL NETWORK S.R.L.","Provider Family":"","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-07-02","Network Type":"Historical network; currently unannounced","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"Historical only: no current adverse-source confirmation found","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"S05, N01","Evidence Summary":"RIPEstat reports AS48974 as not currently announced. It is not in the current Spamhaus ASN-DROP snapshot, and no strong current BPH designation was found during this review.","Analyst Notes":"Retain the alias for historical investigations, but do not keep it in an active ASN-only alert until routing or evidence returns. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS48995","ASN Number":"48995","Network Name":"NOVLINE-AS IE Gilaskhanov Said Visirpashaevich","Aliases":"IE Gilaskhanov Said Visirpashaevich","Provider Family":"","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.23","ipapi Rank":"816","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #816 with 15.23% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"RU:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS49006","ASN Number":"49006","Network Name":"Systems SC ITNS.NET SRL","Aliases":"Systems; ITNS.NET; SC ITNS.NET SRL","Provider Family":"","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-04-24","Network Type":"Historical network or hosting; currently unannounced","Category":"Allocated but long-unannounced manual-review candidate","Evidence Level":"Historical only: no current adverse-source confirmation found","FP Risk":"N/A","Recommended Use":"Disabled pending fresh route visibility and current holder validation.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"S05, N01","Evidence Summary":"RIPEstat reports AS49006 as not currently announced. It is absent from the current Spamhaus ASN-DROP snapshot, and no strong current BPH evidence was identified.","Analyst Notes":"Keep for historical correlation and reactivation monitoring only. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.; Long-unannounced allocated ASN; absence as an origin alone is not proof of retirement.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS49399","ASN Number":"49399","Network Name":"ESAB-2-AS 31173 Services AB","Aliases":"31173 Services AB","Provider Family":"31173.se","RIR Country Code":"SE","Country Name":"Sweden","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.19","ipapi Rank":"762","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #762 with 17.19% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS49443","ASN Number":"49443","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Aliases":"Contrust-Solutions; kontrast.md; Contrust Solutions S.R.L.","Provider Family":"kontrast.md","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-23","Network Type":"Historical network; current ASN-DROP but unannounced","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"High adverse designation, dormant routing","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"254","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS49443 remains in the current Spamhaus ASN-DROP snapshot, but RIPEstat reports it as not currently announced. Retain the high-risk label and watch for reannouncement rather than generating routine active alerts. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. The adverse designation is current, but there is no current route to observe. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS49468","ASN Number":"49468","Network Name":"MAGHOST_RO MAGIT'ST SRL","Aliases":"","Provider Family":"MAGIT'ST SRL","RIR Country Code":"RO","Country Name":"Romania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Conditional fast-flux ASN seed","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Conditional analytic","Actor / Campaign":"Fast-flux phishing infrastructure","Last Evidence":"2026-09-29","Source IDs":"N38, N01","Evidence Summary":"Conditional fast-flux analytic includes this ASN. This supports source-scoped review, not provider-wide malicious attribution.","Analyst Notes":"Do not enable from this source alone.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"RO:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS49588","ASN Number":"49588","Network Name":"SlvNet-as SDS-Vostok Ltd.","Aliases":"SDS-Vostok Ltd.","Provider Family":"slv.net.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.69","ipapi Rank":"951","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #951 with 12.69% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"5","IPsum IPs":"4","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"UA:5"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS49755","ASN Number":"49755","Network Name":"telecom-159-ru LLC SvyazTelecom","Aliases":"LLC SvyazTelecom","Provider Family":"159.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.23","ipapi Rank":"820","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #820 with 15.23% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS49785","ASN Number":"49785","Network Name":"AWIST P.P.H.U AWIST","Aliases":"P.P.H.U AWIST","Provider Family":"inetia.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"33.98","ipapi Rank":"560","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #560 with 33.98% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS49840","ASN Number":"49840","Network Name":"XREALNET Enson Net Ltd","Aliases":"Enson Net Ltd","Provider Family":"ensonnet.com","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.12","ipapi Rank":"733","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #733 with 18.12% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"TR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS49854","ASN Number":"49854","Network Name":"STARLINKCOUNTRY-AS Starlink Country LLC","Aliases":"Starlink Country LLC","Provider Family":"levokumka.net","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.97","ipapi Rank":"735","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #735 with 17.97% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS50015","ASN Number":"50015","Network Name":"HOLINET-AS Aleksandr Butenko","Aliases":"Aleksandr Butenko","Provider Family":"","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.37","ipapi Rank":"962","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #962 with 12.37% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS50138","ASN Number":"50138","Network Name":"CTC-ALFA-AS Centrul Tehnic Comercial Alfa SA","Aliases":"CTC-ALFA-AS; Alfa-inet; Centrul Tehnic Comercial Alfa SA","Provider Family":"","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Fixed-access ISP and business connectivity","Category":"Legacy hosting/VPS watchlist","Evidence Level":"Low: registry and provider classification only","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"S05, X051, N01","Evidence Summary":"RIPEstat currently sees AS50138 announced. Public provider and Moldovan regulator material identify Alfa as an internet access provider. It is not in the current Spamhaus ASN-DROP snapshot, and no strong current BPH designation was found.","Analyst Notes":"This looks like access ISP space rather than dedicated attacker infrastructure. Require stronger identity, device, and behavioral anomalies.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS50174","ASN Number":"50174","Network Name":"INTEXCOM-AS Intexcom OOO","Aliases":"Intexcom OOO","Provider Family":"intexcom.net","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.18","ipapi Rank":"913","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #913 with 13.18% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS50236","ASN Number":"50236","Network Name":"Vertexlink_Communications VertexLink Inc.","Aliases":"Vertexlink_Communications; 62yun.com; VertexLink Inc.","Provider Family":"62yun.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-06-29","Network Type":"Historical hosting or network services; current ASN-DROP but unannounced","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"High adverse designation, dormant routing","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"255","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS50236 is present in the current Spamhaus ASN-DROP snapshot, but RIPEstat reports it as not currently announced. The registry country and Spamhaus country labels differ, reinforcing that country fields should not be used for actor attribution. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Vertexlink_Communications (62yun.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Keep the current adverse designation, but activate alerts only if routing returns or an event resolves to the ASN. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS50308","ASN Number":"50308","Network Name":"FREE50308 Address Limited","Aliases":"FREE50308; Address Limited","Provider Family":"","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2024-12-21","Network Type":"Historical IP-address or network-services ASN; currently unannounced","Category":"Allocated but long-unannounced manual-review candidate","Evidence Level":"Historical only: no current adverse-source confirmation found","FP Risk":"N/A","Recommended Use":"Disabled pending fresh route visibility and current holder validation.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"S05, N01","Evidence Summary":"RIPEstat reports AS50308 as not currently announced. It is absent from current Spamhaus ASN-DROP and no strong current BPH evidence was identified.","Analyst Notes":"Retain the alias for past investigations, but remove it from live matching until it is routed again. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.; Long-unannounced allocated ASN; absence as an origin alone is not proof of retirement.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS50467","ASN Number":"50467","Network Name":"BESKID-MEDIA-AS Beskid Media Sp. z o.o.","Aliases":"Beskid Media Sp. z o.o.","Provider Family":"beskidmedia.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.87","ipapi Rank":"881","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #881 with 13.87% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS50935","ASN Number":"50935","Network Name":"International-Hosting-Solutions-AS INTERNATIONAL HOSTING SOLUTIONS LLP","Aliases":"International-Hosting-Solutions-AS; INTERNATIONAL HOSTING SOLUTIONS LLP","Provider Family":"","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2021-10-26","Network Type":"Historical hosting ASN; currently unannounced","Category":"Allocated but long-unannounced manual-review candidate","Evidence Level":"Historical only: no current adverse-source confirmation found","FP Risk":"N/A","Recommended Use":"Disabled pending fresh route visibility and current holder validation.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"S05, N01","Evidence Summary":"RIPEstat reports AS50935 as not currently announced. It is not in the current Spamhaus ASN-DROP snapshot, and no strong current BPH designation was found.","Analyst Notes":"The provider name suggests hosting, but inactive routing makes it a historical rather than an operational detector. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.; Long-unannounced allocated ASN; absence as an origin alone is not proof of retirement.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS51045","ASN Number":"51045","Network Name":"DEMENIN-AS DEMENIN B.V.","Aliases":"DEMENIN-AS; bignet.ua; DEMENIN B.V.","Provider Family":"bignet.ua","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2013-11-28","Network Type":"Historical hosting or leased infrastructure; current ASN-DROP but unannounced","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"High adverse designation, dormant routing","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"256","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS51045 remains in the current Spamhaus ASN-DROP snapshot under bignet.ua, but RIPEstat reports it as not currently announced. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DEMENIN-AS (bignet.ua).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Keep the high-risk history and watch for routing return. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS51104","ASN Number":"51104","Network Name":"Remini-Telecom VIP GROUP (S.A.R.L)","Aliases":"VIP GROUP (S.A.R.L)","Provider Family":"","RIR Country Code":"LB","Country Name":"Lebanon","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.36","ipapi Rank":"811","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #811 with 15.36% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS51246","ASN Number":"51246","Network Name":"RASVTV RASV-TV SRL","Aliases":"RASVTV; rasvtv.md; RASV-TV SRL","Provider Family":"","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Local cable broadband and television ISP","Category":"Legacy hosting/VPS watchlist","Evidence Level":"Low: provider classification only","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"S05, X052, N01","Evidence Summary":"RIPEstat currently sees AS51246 announced. RASV-TV describes itself as a local cable internet and digital television provider. It is not in current Spamhaus ASN-DROP and no strong current BPH designation was found.","Analyst Notes":"Residential ISP traffic can include legitimate users and compromised endpoints. Use behavior and device signals, not ASN alone.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS51381","ASN Number":"51381","Network Name":"ELITETEAM-PEERING-AZ1 1337TEAM LIMITED","Aliases":"ELITETEAM-PEERING-AZ1; ELITETEAM; eliteteam.to; 1337TEAM LIMITED (ELITETEAM Seychelles); 1337TEAM LIMITED","Provider Family":"ELITETEAM / 1337TEAM","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-02-28","Network Type":"Bulletproof / high-risk hosting family","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"High: published BPH analysis plus current Spamhaus ASN-DROP","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"258","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, S16, N01, S03","Evidence Summary":"Team Cymru identified ELITETEAM/1337TEAM as a bulletproof hosting provider and associated AS51381 with its infrastructure. AS51381 remains in current Spamhaus ASN-DROP, but RIPEstat reports no current announcement. Team Cymru linked four ASNs to ELITETEAM/1337TEAM. AS56873 and AS51381 remain in current ASN-DROP even though current RIPEstat enrichment reports them unannounced; AS39770 and AS60424 are historical/unannounced. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ELITETEAM-PEERING-AZ1 (eliteteam.to).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Strong source-confirmed BPH history, but no live route. Escalate immediately if it reappears or an event resolves to it. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS51488","ASN Number":"51488","Network Name":"GARANTTELESETI-AS Garant-Teleseti LLC","Aliases":"Garant-Teleseti LLC","Provider Family":"aogarant.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.14","ipapi Rank":"709","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #709 with 19.14% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS52008","ASN Number":"52008","Network Name":"NESTER-NET NesterTelecom LLC","Aliases":"NesterTelecom LLC","Provider Family":"nester.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"71.43","ipapi Rank":"478","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #478 with 71.43% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RU:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS52045","ASN Number":"52045","Network Name":"VIZIT-AS PTRC-VIZIT","Aliases":"PTRC-VIZIT","Provider Family":"","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.36","ipapi Rank":"729","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #729 with 18.36% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS52490","ASN Number":"52490","Network Name":"AS52490 - COOPERATIVA DE ELECTRICIDAD DE PEDRO LURO","Aliases":"COOPERATIVA DE ELECTRICIDAD DE PEDR","Provider Family":"","RIR Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"38.13","ipapi Rank":"545","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #545 with 38.13% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"4","IPsum IPs":"4","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"AR:4"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS52543","ASN Number":"52543","Network Name":"AS52543 - ATL Comercio e Servicos de Informatica Ltda","Aliases":"ATL Comércio e Serviços de Informática L","Provider Family":"microsattelecom.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.93","ipapi Rank":"877","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #877 with 13.93% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS52630","ASN Number":"52630","Network Name":"AS52630 - MOTTANET TI - SERVICOS DE TECNOLOGIA DA INFO","Aliases":"MOTTANET TI - SERVICOS DE TECNOLOGIA","Provider Family":"mottanet.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"25.39","ipapi Rank":"618","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #618 with 25.39% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS52635","ASN Number":"52635","Network Name":"AS52635 - SPEEDCONNECT - TECNOLOGIA E EQUIPAMENTOS","Aliases":"SPEEDCONNECT - TECNOLOGIA E EQUIPAMENTOS","Provider Family":"speedconnectfibra.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.09","ipapi Rank":"919","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #919 with 13.09% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS52688","ASN Number":"52688","Network Name":"AS52688 - FATIMA VIDEO ELETRONICA LTDA ME","Aliases":"FATIMA VIDEO ELETRONICA LTDA ME","Provider Family":"fatimavideo.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"33.33","ipapi Rank":"567","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #567 with 33.33% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS52780","ASN Number":"52780","Network Name":"AS52780 - MAP Piumhi Ltda - ME","Aliases":"MAP Piumhi Ltda - ME","Provider Family":"mapminas.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"49.17","ipapi Rank":"521","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #521 with 49.17% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS52904","ASN Number":"52904","Network Name":"AS52904 - Multpontos Telecomunicacoes Ltda - ME","Aliases":"Multpontos Telecomunicações Ltda - ME","Provider Family":"multpontos.net.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"21.74","ipapi Rank":"664","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #664 with 21.74% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS52937","ASN Number":"52937","Network Name":"AS52937 - FHP TELECOMUNICACAO E COM VAREJISTA DE PRODUTOS DE","Aliases":"FHP TELECOMUNICACAO E COM VAREJISTA DE P","Provider Family":"fhpfibra.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.7","ipapi Rank":"775","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #775 with 16.7% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS53003","ASN Number":"53003","Network Name":"AS53003 - EVOLUNET PROVEDORA DE INTERNET LTDA PE","Aliases":"EVOLUNET PROVEDORA DE INTERNET LTDA PE","Provider Family":"evolunetcorp.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.38","ipapi Rank":"757","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #757 with 17.38% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS53072","ASN Number":"53072","Network Name":"AS53072 - INETVIP TELECOM LTDA","Aliases":"INETVIP TELECOM LTDA","Provider Family":"inetvip.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"21.21","ipapi Rank":"672","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #672 with 21.21% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS53158","ASN Number":"53158","Network Name":"AS53158 - Net Turbo Telecom","Aliases":"Net Turbo Telecom","Provider Family":"netturbo.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"67.12","ipapi Rank":"479","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #479 with 67.12% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS54113","ASN Number":"54113","Network Name":"FASTLY - Fastly, Inc.","Aliases":"","Provider Family":"Fastly","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Broad cloud/CDN control row","Evidence Level":"Context","FP Risk":"Very High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N01","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS55748","ASN Number":"55748","Network Name":"MORSE-JP - 7-9-10 Nishi-Shinjuku","Aliases":"MORSE-JP; MORSE; morsejp.com; 7-9-10 Nishi-Shinjuku / MORSE-JP","Provider Family":"morsejp.com","RIR Country Code":"JP","Country Name":"Japan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"","Network Type":"Historical network; current ASN-DROP but unannounced","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"High adverse designation, dormant routing","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"261","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS55748 remains in current Spamhaus ASN-DROP, but RIPEstat reports it as not currently announced. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as MORSE-JP (morsejp.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Preserve the current adverse designation, but no operational matching is expected without routing. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS56268","ASN Number":"56268","Network Name":"SREERAM-NED1-IN - Northeast Dataa Network Pvt Ltd","Aliases":"Northeast Dataa Network Pvt Ltd","Provider Family":"nedataa.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"21.51","ipapi Rank":"669","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #669 with 21.51% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"3","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"2","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"IN:3"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS56291","ASN Number":"56291","Network Name":"ACE-AS-AP - Ace, Inc.","Aliases":"ACE-AS-AP; ace-idc.com; Ace, Inc.","Provider Family":"ace-idc.com","RIR Country Code":"JP","Country Name":"Japan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-08-29","Network Type":"Historical hosting or data-center ASN; current ASN-DROP but unannounced","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"High adverse designation, dormant routing","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"262","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, N01, S03","Evidence Summary":"AS56291 is in the current Spamhaus ASN-DROP snapshot, but RIPEstat reports it as not currently announced. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ACE-AS-AP (ace-idc.com).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Keep high-risk history and alert on reactivation rather than current ASN-only events. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS56400","ASN Number":"56400","Network Name":"ASSPDChernega SPD Chernega Aleksandr Anatolevich","Aliases":"SPD Chernega Aleksandr Anatolevich","Provider Family":"flycom.net.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.95","ipapi Rank":"876","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #876 with 13.95% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"41","IPsum IPs":"17","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"36","Talos 2024 IPs":"0","Multi-list IPs":"12","Listed-IP Country Mix":"UA:41"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS56541","ASN Number":"56541","Network Name":"KOMETA-AS KOMETA LLC","Aliases":"KOMETA LLC","Provider Family":"pinspb.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.92","ipapi Rank":"878","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #878 with 13.92% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS56606","ASN Number":"56606","Network Name":"NERACOM-AS NERACOM Ltd.","Aliases":"NERACOM Ltd.","Provider Family":"neracom.bg","RIR Country Code":"BG","Country Name":"Bulgaria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.06","ipapi Rank":"866","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #866 with 14.06% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS56812","ASN Number":"56812","Network Name":"ASZARKO CHP Zarko Alexandr Ivanovich","Aliases":"CHP Zarko Alexandr Ivanovich","Provider Family":"komsomolske.net","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"20.34","ipapi Rank":"683","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #683 with 20.34% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"39","IPsum IPs":"34","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"10","Talos 2024 IPs":"0","Multi-list IPs":"5","Listed-IP Country Mix":"UA:39"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS56873","ASN Number":"56873","Network Name":"ELITETEAM-ANTIDDOS 1337TEAM LIMITED","Aliases":"ELITETEAM-ANTIDDOS; ELITETEAM; eliteteam.to; 1337TEAM LIMITED (ELITETEAM); 1337TEAM LIMITED","Provider Family":"ELITETEAM / 1337TEAM","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-05-02","Network Type":"Bulletproof / high-risk hosting family","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"High: published BPH analysis plus current Spamhaus ASN-DROP","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"265","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, S16, N01, S03","Evidence Summary":"Team Cymru identified ELITETEAM/1337TEAM as a bulletproof hosting provider and associated AS56873 with its infrastructure. The ASN remains in current Spamhaus ASN-DROP, but RIPEstat reports no current announcement. Team Cymru linked four ASNs to ELITETEAM/1337TEAM. AS56873 and AS51381 remain in current ASN-DROP even though current RIPEstat enrichment reports them unannounced; AS39770 and AS60424 are historical/unannounced. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ELITETEAM-ANTIDDOS (eliteteam.to).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Strong source-confirmed BPH history, but no live route. Escalate on reannouncement. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS56985","ASN Number":"56985","Network Name":"RUSTEL-AS RUSTEL LLC","Aliases":"RUSTEL LLC","Provider Family":"telsto.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.89","ipapi Rank":"925","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #925 with 12.89% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RU:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS57013","ASN Number":"57013","Network Name":"EURASIA-STAR-AS Eurasia-Star LLP","Aliases":"Eurasia-Star LLP","Provider Family":"esnet.kz","RIR Country Code":"KZ","Country Name":"Kazakhstan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"20.61","ipapi Rank":"679","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #679 with 20.61% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"KZ:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS57403","ASN Number":"57403","Network Name":"HAZI HFM S.R.L","Aliases":"HFM S.R.L","Provider Family":"hazi.ro","RIR Country Code":"RO","Country Name":"Romania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.6","ipapi Rank":"780","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #780 with 16.6% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RO:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS57411","ASN Number":"57411","Network Name":"NOVOTEHNIKS-AS Novotehniks LLC","Aliases":"Novotehniks LLC","Provider Family":"ntx55.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"21.88","ipapi Rank":"663","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #663 with 21.88% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RU:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS57523","ASN Number":"57523","Network Name":"changway-as Chang Way Technologies Co. Limited","Aliases":"Chang Way Technologies; changway-as; Chang Way Technologies Co. Limited; changway.hk; Chang Way Technologies Co. Limited (bulletproof hosting); Chang Way Technologies Co. Limited (historical)","Provider Family":"Chang Way Technologies","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-02-04","Network Type":"Bulletproof / high-risk hosting family","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"High","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"267","Login / Identity Evidence":"No","Actor / Campaign":"adversary command-and-control hosting","Last Evidence":"2026-09-29","Source IDs":"S01, S02, S05, X057, N01, S03","Evidence Summary":"Recorded Future's 2022 report explicitly named Chang Way Technologies as a known BPH provider and mapped AS57523 to it. Spamhaus still lists the ASN in its 2026-09-15 ASN-DROP snapshot, but it is not currently announcing routes. Recorded Future's 2022 adversary-infrastructure report listed AS57523 among networks observed hosting Cobalt Strike. It remains in current Spamhaus ASN-DROP, but RIPEstat reports it as not currently announced. This is infrastructure evidence, not nationality attribution. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as changway-as (changway.hk).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Strong adverse history and current feed designation, but no current route. High historical provider classification; no basis for current enforcement while withdrawn. Not announcing routes on 2026-09-15. Move from active deny/watch logic to a tombstone with holder-change checks. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS57558","ASN Number":"57558","Network Name":"METIS-AS METIS S.R.L.","Aliases":"METIS S.R.L.","Provider Family":"metissrl.it","RIR Country Code":"IT","Country Name":"Italy","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"29.3","ipapi Rank":"586","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #586 with 29.3% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"51","IPsum IPs":"50","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"IT:51"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS57789","ASN Number":"57789","Network Name":"HOMENET HomeNet Technologies Sp. z o.o.","Aliases":"HomeNet Technologies Sp. z o.o.","Provider Family":"home-net.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"28.95","ipapi Rank":"588","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #588 with 28.95% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS57916","ASN Number":"57916","Network Name":"LAROM-AS Larom TV SRL","Aliases":"LAROM-AS; Larom TV SRL","Provider Family":"","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-09-13","Network Type":"Historical cable or access ISP; currently unannounced","Category":"Allocated but long-unannounced manual-review candidate","Evidence Level":"Historical only: no current adverse-source confirmation found","FP Risk":"N/A","Recommended Use":"Disabled pending fresh route visibility and current holder validation.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"S05, N01","Evidence Summary":"RIPEstat reports AS57916 as not currently announced. It is absent from current Spamhaus ASN-DROP and no strong current BPH designation was found.","Analyst Notes":"Inactive access-provider history is not suitable for a live ASN-only detector. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.; Long-unannounced allocated ASN; absence as an origin alone is not proof of retirement.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS58070","ASN Number":"58070","Network Name":"KSN-AS Kriukov Sergei Nikolaevich","Aliases":"Kriukov Sergei Nikolaevich","Provider Family":"","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.28","ipapi Rank":"905","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #905 with 13.28% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS58087","ASN Number":"58087","Network Name":"FlorianKolb Florian Kolb","Aliases":"Florian Kolb","Provider Family":"datalix.de","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.96","ipapi Rank":"832","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #832 with 14.96% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"26","IPsum IPs":"20","IPsum Score >=3":"2","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"15","Talos 2024 IPs":"0","Multi-list IPs":"10","Listed-IP Country Mix":"DE:26"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS58347","ASN Number":"58347","Network Name":"AIK-AS AiK LLC","Aliases":"AiK LLC","Provider Family":"gwave.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"26.3","ipapi Rank":"611","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #611 with 26.3% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS58401","ASN Number":"58401","Network Name":"XROUTE-AS-ID - PT. DEWATA TELEMATIKA","Aliases":"PT. DEWATA TELEMATIKA","Provider Family":"detelnetworks.id","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.11","ipapi Rank":"979","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #979 with 12.11% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS58427","ASN Number":"58427","Network Name":"GEC-AF - Global Entourage Services","Aliases":"Global Entourage Services","Provider Family":"gec.af","RIR Country Code":"AF","Country Name":"Afghanistan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.77","ipapi Rank":"837","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #837 with 14.77% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS59392","ASN Number":"59392","Network Name":"FLASH-INTERNET-AS IE Valevskaya Elena Evgenevna","Aliases":"IE Valevskaya Elena Evgenevna","Provider Family":"","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #968 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS59574","ASN Number":"59574","Network Name":"AS-STUPINO-NET Limited Liability Company SKS Telecom","Aliases":"Limited Liability Company SKS Telecom","Provider Family":"stupino.net","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.78","ipapi Rank":"887","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #887 with 13.78% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RU:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS59847","ASN Number":"59847","Network Name":"WIRAC WIRAC.NET d.o.o.","Aliases":"WIRAC.NET d.o.o.","Provider Family":"wirac.ba","RIR Country Code":"BA","Country Name":"Bosnia & Herzegovina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #999 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS60005","ASN Number":"60005","Network Name":"IT-service-AS IT-service LLC","Aliases":"IT-service LLC","Provider Family":"","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.45","ipapi Rank":"855","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #855 with 14.45% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS60017","ASN Number":"60017","Network Name":"FASTLINES FASTLINES SRL","Aliases":"FASTLINES SRL","Provider Family":"fastlines.it","RIR Country Code":"IT","Country Name":"Italy","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.34","ipapi Rank":"700","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #700 with 19.34% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"3","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"IT:3"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS60246","ASN Number":"60246","Network Name":"PG-19 Consumer Internet Cooperative PG-19","Aliases":"Consumer Internet Cooperative PG-19","Provider Family":"pg19.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"11.89","ipapi Rank":"994","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #994 with 11.89% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"34","IPsum IPs":"17","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"30","Talos 2024 IPs":"0","Multi-list IPs":"13","Listed-IP Country Mix":"RU:34"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS60286","ASN Number":"60286","Network Name":"STEPNET-KZ-AS Agency-KA Ltd.","Aliases":"Agency-KA Ltd.","Provider Family":"stepnet.kz","RIR Country Code":"KZ","Country Name":"Kazakhstan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.16","ipapi Rank":"826","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #826 with 15.16% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS60729","ASN Number":"60729","Network Name":"TORSERVERS-NET Stiftung Erneuerbare Freiheit","Aliases":"Stiftung Erneuerbare Freiheit","Provider Family":"renewablefreedom.org","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"60.81","ipapi Rank":"491","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #491 with 60.81% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"169","IPsum IPs":"162","IPsum Score >=3":"34","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"140","Talos 2024 IPs":"89","Multi-list IPs":"140","Listed-IP Country Mix":"DE:110, US:59"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS61367","ASN Number":"61367","Network Name":"ASBALKHASH TOO \"B-TEL\"","Aliases":"TOO B-TEL","Provider Family":"71036.kz","RIR Country Code":"KZ","Country Name":"Kazakhstan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.89","ipapi Rank":"879","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #879 with 13.89% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"KZ:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS61748","ASN Number":"61748","Network Name":"AS61748 - Dkirosnet Servicos de Internet","Aliases":"Dkirosnet Serviços de Internet","Provider Family":"d-kiros.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"24.15","ipapi Rank":"633","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #633 with 24.15% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS61756","ASN Number":"61756","Network Name":"AS61756 - NETPONTAL PROVEDOR DE INTERNET LTDA - ME","Aliases":"NETPONTAL PROVEDOR DE INTERNET LTDA - ME","Provider Family":"netpontal.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"50","ipapi Rank":"514","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #514 with 50% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS61782","ASN Number":"61782","Network Name":"AS61782 - WNNet Telecom","Aliases":"WNNet Telecom","Provider Family":"wnnet.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"33.33","ipapi Rank":"569","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #569 with 33.33% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS61851","ASN Number":"61851","Network Name":"AS61851 - Garra Fibra","Aliases":"Garra Fibra","Provider Family":"garratelecom.net.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"33.56","ipapi Rank":"561","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #561 with 33.56% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS63179","ASN Number":"63179","Network Name":"TWITTER - Twitter Inc.","Aliases":"Twitter Inc.","Provider Family":"x.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"21.11","ipapi Rank":"673","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #673 with 21.11% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS64429","ASN Number":"64429","Network Name":"OPTIKNET-AS DDS Service LLC","Aliases":"DDS Service LLC","Provider Family":"optiknet.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"31.03","ipapi Rank":"579","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #579 with 31.03% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS132073","ASN Number":"132073","Network Name":"WAVENET-AS-AP - Wave Net","Aliases":"Wave Net","Provider Family":"wave-net.pl","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #975 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BD:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS132206","ASN Number":"132206","Network Name":"DATAHUB-VN - DC DIGITAL DATA HUB COMPANY LIMITED","Aliases":"DC DIGITAL DATA HUB COMPANY LIMITED","Provider Family":"datahub.vn","RIR Country Code":"VN","Country Name":"Vietnam","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"99.41","ipapi Rank":"461","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #461 with 99.41% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"VN:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS132438","ASN Number":"132438","Network Name":"APONIT-AS-AP - Evan Ahmed Bhuiyan t/a APON IT","Aliases":"APON IT","Provider Family":"aponit.com","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.18","ipapi Rank":"914","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #914 with 13.18% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS132934","ASN Number":"132934","Network Name":"SKYMAX-AS - Skymax Broadband Services Pvt. Ltd.","Aliases":"Skymax Broadband Services Pvt. Ltd.","Provider Family":"apjii.or.id","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.34","ipapi Rank":"900","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #900 with 13.34% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"IN:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS134299","ASN Number":"134299","Network Name":"GSTECH-AS - Gstech Software Systems Pvt Ltd","Aliases":"Gstech Software Systems Pvt Ltd","Provider Family":"preciousnetcom.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-09-20","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the Very High band at rank #545 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS135488","ASN Number":"135488","Network Name":"IDNIC-OTHMARNETWORK-AS-ID - PT OTHMAR MATRA MEDIA","Aliases":"IDNIC OTHMARNETWORK AS ID","Provider Family":"othmarnetwork.com","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.8","ipapi Rank":"771","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #771 with 16.8% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS135683","ASN Number":"135683","Network Name":"NETNCR-AS - Netncr Technology Pvt. Ltd.","Aliases":"Netncr Technology Pvt. Ltd.","Provider Family":"netncr.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.01","ipapi Rank":"985","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #985 with 12.01% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"IN:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS135765","ASN Number":"135765","Network Name":"WEBMAX33-AS-IN - WEBMAX NETWORK SOLUTIONS PRIVATE LIMITED","Aliases":"WEBMAX NETWORK SOLUTIONS PRIVATE LIMITED","Provider Family":"webmaxnet.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.95","ipapi Rank":"712","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #712 with 18.95% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS135815","ASN Number":"135815","Network Name":"NETREXO-AS - Netrexo Communications Private Limited","Aliases":"Netrexo Communications Private Limited","Provider Family":"netrexo.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.53","ipapi Rank":"809","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #809 with 15.53% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS135818","ASN Number":"135818","Network Name":"GTNCPL-AS - Green Tech Net Com Pvt Ltd","Aliases":"Green Tech Net Com Pvt Ltd","Provider Family":"gtncpl.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.6","ipapi Rank":"779","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #779 with 16.6% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS135850","ASN Number":"135850","Network Name":"NSNPLMRJ-AS - Net Sathi Networks Pvt. Ltd","Aliases":"Net Sathi Networks Pvt. Ltd","Provider Family":"apjii.or.id","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"20.12","ipapi Rank":"688","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #688 with 20.12% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS135915","ASN Number":"135915","Network Name":"TLSOFT-AS-VN - 8 Floor, 96-98 Dao Duy Anh, Phu Nhuan, HCMC","Aliases":"TLSOFT AS VN","Provider Family":"tlsoft.vn","RIR Country Code":"VN","Country Name":"Vietnam","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"33.5","ipapi Rank":"562","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #562 with 33.5% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS135981","ASN Number":"135981","Network Name":"VISUALVIET-AS-VN - VisualViet Company Limited","Aliases":"VisualViet Company Limited","Provider Family":"apjii.or.id","RIR Country Code":"VN","Country Name":"Vietnam","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.24","ipapi Rank":"969","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #969 with 12.24% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS136319","ASN Number":"136319","Network Name":"APLL-AS-IN - Acebrowse Private Ltd","Aliases":"Acebrowse Private Ltd","Provider Family":"acebrowse.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"21.58","ipapi Rank":"666","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #666 with 21.58% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS136676","ASN Number":"136676","Network Name":"KADSYSCON-AS - Kad-syscon Infotech Private Limited","Aliases":"Kad-syscon Infotech Private Limited","Provider Family":"apjii.or.id","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.82","ipapi Rank":"798","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #798 with 15.82% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS136879","ASN Number":"136879","Network Name":"JARINDO-AS-ID - DELAPAN BIT","Aliases":"PT. Media Jaringan Indonesia","Provider Family":"jarindo.id","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.93","ipapi Rank":"768","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #768 with 16.93% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"4","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"4","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"ID:4"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS138183","ASN Number":"138183","Network Name":"MSCOMPUTERMATE-AS-AP - Computer Mate","Aliases":"Computer Mate","Provider Family":"computermate.net","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.28","ipapi Rank":"907","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #907 with 13.28% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"8","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"6","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"BD:8"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS138655","ASN Number":"138655","Network Name":"TES-PL-AS-AP - Trans World Enterprise Services (Private) Limited","Aliases":"Trans World Enterprise Services (Private","Provider Family":"tes.com.pk","RIR Country Code":"PK","Country Name":"Pakistan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #907 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"4","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"PK:4"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS138953","ASN Number":"138953","Network Name":"TOPNETWORK-AS-AP - Top Network","Aliases":"Top Network","Provider Family":"topnetbd.com","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"20.31","ipapi Rank":"684","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #684 with 20.31% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BD:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS138992","ASN Number":"138992","Network Name":"AYSHAITSOLUTIONS-AS-AP - Aysha IT Solutions","Aliases":"Aysha IT Solutions","Provider Family":"ayshait.net","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #989 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS139202","ASN Number":"139202","Network Name":"POWERMEDIA-AS-AP - Power Media","Aliases":"Power Media","Provider Family":"powermediabd.net","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.97","ipapi Rank":"736","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #736 with 17.97% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS139347","ASN Number":"139347","Network Name":"RVCYBERWORLD-AS-AP - Md Masud Rana Roni t/a RV Cyber World","Aliases":"RV Cyber World","Provider Family":"rvcyberworld.net","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.63","ipapi Rank":"805","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #805 with 15.63% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS139381","ASN Number":"139381","Network Name":"IDNIC-CITRA-BERDIKARI-NUSANTARA-AS-ID - PT.CITRA BERDIKARI NUSANTARA","Aliases":"PT.CITRA BERDIKARI NUSANTARA","Provider Family":"citraberdikari.co.id","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"20.12","ipapi Rank":"689","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #689 with 20.12% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"4","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"4","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"ID:4"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS139549","ASN Number":"139549","Network Name":"CRISPENT-AS - Crisp Enterprises","Aliases":"Crisp Enterprises","Provider Family":"apjii.or.id","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.54","ipapi Rank":"781","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #781 with 16.54% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"9","IPsum IPs":"6","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"4","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"IN:9"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS139678","ASN Number":"139678","Network Name":"JOYDEBPUR-AS-AP - Joydebpur Network","Aliases":"Joydebpur network","Provider Family":"joydebpurnetwork.net","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.28","ipapi Rank":"909","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #909 with 13.28% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS139718","ASN Number":"139718","Network Name":"TORNADO3-AS-AP - Tornado Networks (Pvt.) Limited","Aliases":"Tornado Networks (Pvt.) Limited","Provider Family":"tornado.com.pk","RIR Country Code":"PK","Country Name":"Pakistan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"26.95","ipapi Rank":"604","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #604 with 26.95% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS139728","ASN Number":"139728","Network Name":"P3C-AS-AP - Planet Three Communication","Aliases":"Planet Three Communication","Provider Family":"planet3communication.com","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.11","ipapi Rank":"980","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #980 with 12.11% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS139779","ASN Number":"139779","Network Name":"NHB2-AS-AP - Net@Home-Bamoul Branch","Aliases":"Net @ Home","Provider Family":"netathomebd.net","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #988 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS139839","ASN Number":"139839","Network Name":"ZERONET-AS-AP - ZeroNET","Aliases":"ZeroNET","Provider Family":"zeronetbd.net","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.14","ipapi Rank":"706","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #706 with 19.14% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS139879","ASN Number":"139879","Network Name":"GALAXY-AS-AP - Galaxy Broadband","Aliases":"Galaxy Broadband (pvt.) Ltd.","Provider Family":"galaxy.net.pk","RIR Country Code":"PK","Country Name":"Pakistan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.81","ipapi Rank":"941","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #941 with 12.81% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"43","IPsum IPs":"37","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"17","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"12","Listed-IP Country Mix":"PK:43"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS140026","ASN Number":"140026","Network Name":"TIMORNET-AS-ID - PT. KUPANG INTERMEDIA","Aliases":"PT. KUPANG INTERMEDIA","Provider Family":"timornet.id","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"39.39","ipapi Rank":"541","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #541 with 39.39% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"6","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"4","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"SG:4, ID:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS140210","ASN Number":"140210","Network Name":"CONNECTX-AS-AP - ConnectX","Aliases":"ConnectX","Provider Family":"connectx.pk","RIR Country Code":"PK","Country Name":"Pakistan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.11","ipapi Rank":"981","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #981 with 12.11% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS140807","ASN Number":"140807","Network Name":"TND-AS-VN - Nguyen Ngoc Thanh Trading Limited Company","Aliases":"Nguyen Ngoc Thanh Trading Limited Compan","Provider Family":"tnd.vn","RIR Country Code":"VN","Country Name":"Vietnam","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"21.56","ipapi Rank":"667","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #667 with 21.56% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS140906","ASN Number":"140906","Network Name":"MAYASOFT-AS-AP - MAYA SOFT","Aliases":"MAYA SOFT","Provider Family":"mayasoftbd.net","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.06","ipapi Rank":"869","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #869 with 14.06% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS140923","ASN Number":"140923","Network Name":"GLOBALLINK-AS-AP - Global Link","Aliases":"Global Link","Provider Family":"globallinkbd.net","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"39.06","ipapi Rank":"542","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #542 with 39.06% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS140952","ASN Number":"140952","Network Name":"STL-AS-AP - Strong Technology, LLC","Aliases":"","Provider Family":"Strong Technology / NetProtect","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"United States","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Commercial VPN / hosting / proxy","Category":"Commercial VPN provider family expansion","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"StrongVPN / Strong Technology family","Last Evidence":"2026-09-15","Source IDs":"N35, N36, N01","Evidence Summary":"Active Strong Technology / NetProtect family ASN without sufficient direct campaign-time evidence for automatic monitoring. Disabled pending local need and validation.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"0","Current Listed IPs":"24","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"24","Multi-list IPs":"0","Listed-IP Country Mix":"PL:10, AU:9, US:4, KR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS141098","ASN Number":"141098","Network Name":"MULTIMEDIALINKTECH-AS-ID - PT Multimedia Link Technology","Aliases":"MULTIMEDIALINKTECH AS ID","Provider Family":"multimedialinktech.net","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #974 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"20","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"19","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"ID:20"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS141127","ASN Number":"141127","Network Name":"IDNIC-CDNNET-AS-ID - PT Anugerah Cimanuk Raya","Aliases":"PT. Anugerah Cimanuk Raya","Provider Family":"","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.17","ipapi Rank":"973","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #973 with 12.17% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"19","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"16","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"ID:19"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS141295","ASN Number":"141295","Network Name":"MAPIT-AS-IN - Madhya Pradesh Agency For Promotion Of Information Technology","Aliases":"Madhya Pradesh Agency For Promotion Of","Provider Family":"mapit.gov.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Government","Category":"High-abuse government review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.23","ipapi Rank":"817","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this government ASN #817 with 15.23% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"2","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"IN:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS141347","ASN Number":"141347","Network Name":"M7STL-AS-AP - 7 Star Telecom (Private) Limited","Aliases":"7 Star Telecom (Private) Limited","Provider Family":"7startelecom.net","RIR Country Code":"PK","Country Name":"Pakistan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"24.61","ipapi Rank":"629","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #629 with 24.61% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS141536","ASN Number":"141536","Network Name":"INTERLOK-AS-IN - Interlock Communication","Aliases":"Interlock Communication","Provider Family":"","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.26","ipapi Rank":"860","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #860 with 14.26% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS141642","ASN Number":"141642","Network Name":"IDNIC-RINGNET-AS-ID - PT Ring Media Nusantara","Aliases":"IDNIC RINGNET AS ID","Provider Family":"ring.net.id","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #928 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"27","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"26","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"ID:27"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS141737","ASN Number":"141737","Network Name":"RAPIDNETWORK-AS-AP - Rapid Network","Aliases":"Rapid Network","Provider Family":"rapidnetworkbd.com","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"21.48","ipapi Rank":"670","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #670 with 21.48% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS141787","ASN Number":"141787","Network Name":"LINKOTEK-AS - LINKOTEK NETWORK PRIVATE LIMITED","Aliases":"LINKOTEK NETWORK PRIVATE LIMITED","Provider Family":"linkotek.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"29.69","ipapi Rank":"585","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #585 with 29.69% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS141870","ASN Number":"141870","Network Name":"GVREDDY-AS-IN - GV REDDY BROADBAND SERVICES","Aliases":"GVREDDY AS IN","Provider Family":"","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"23.05","ipapi Rank":"651","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #651 with 23.05% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"6","IPsum IPs":"6","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"IN:6"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS141874","ASN Number":"141874","Network Name":"DISHACR2-AS-IN - DISHA INFOCARE","Aliases":"DISHA INFOCARE","Provider Family":"","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.38","ipapi Rank":"756","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #756 with 17.38% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS142015","ASN Number":"142015","Network Name":"FOXPROTECHNOLOGY-AS-AP - Foxpro Technology","Aliases":"Foxpro Technology","Provider Family":"foxpro.com.bd","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"23.05","ipapi Rank":"650","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #650 with 23.05% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS142352","ASN Number":"142352","Network Name":"IDNIC-TAHTA-ID - PT. PRATAMA HASTA UTAMA SOLUSINDO","Aliases":"PT. PRATAMA HASTA UTAMA SOLUSINDO","Provider Family":"tahtasolusindo.id","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.58","ipapi Rank":"750","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #750 with 17.58% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"68","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"68","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"HK:51, ID:17"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS142627","ASN Number":"142627","Network Name":"MULTILINK-AS-AP - Multilink International","Aliases":"Multilink International","Provider Family":"multilinkisp.com","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.77","ipapi Rank":"745","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #745 with 17.77% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"19","IPsum IPs":"19","IPsum Score >=3":"10","IPsum Score >=5":"1","Open-Proxy IPs":"0","Data-Shield IPs":"16","Talos 2024 IPs":"0","Multi-list IPs":"16","Listed-IP Country Mix":"BD:19"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS142647","ASN Number":"142647","Network Name":"NAN-AS-AP - Nasstec Airnet Networks Private Limited","Aliases":"Nasstec Airnet Networks Private Limited","Provider Family":"nasstecairnet.net.pk","RIR Country Code":"PK","Country Name":"Pakistan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #906 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"70","IPsum IPs":"39","IPsum Score >=3":"3","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"57","Talos 2024 IPs":"0","Multi-list IPs":"26","Listed-IP Country Mix":"PK:70"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS147006","ASN Number":"147006","Network Name":"STARIT-AS-AP - Star IT","Aliases":"Star IT","Provider Family":"staritisp.com","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.97","ipapi Rank":"738","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #738 with 17.97% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS149179","ASN Number":"149179","Network Name":"NET6-AS-AP - Net Express","Aliases":"Net Express","Provider Family":"netexpress.info","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"42.97","ipapi Rank":"534","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #534 with 42.97% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS149270","ASN Number":"149270","Network Name":"LUCKYNET2-AS-IN - Lucky Internet Services Pvt Ltd","Aliases":"Lucky Internet Services Pvt Ltd","Provider Family":"luckyisp.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"24.41","ipapi Rank":"630","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #630 with 24.41% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS149561","ASN Number":"149561","Network Name":"NBPLRAJ-AS-IN - 777 Network Broadband Private Limited","Aliases":"777 Network Broadband Private Limited","Provider Family":"777network.net","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"21.88","ipapi Rank":"661","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #661 with 21.88% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS149638","ASN Number":"149638","Network Name":"ELMAMULTIMEDIA-AS-AP - Elma Multimedia","Aliases":"Elma Multimedia","Provider Family":"elmamultimedia.com","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #990 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS149653","ASN Number":"149653","Network Name":"FAISAL-AS-AP - Faisal Network","Aliases":"Faisal Network","Provider Family":"faisalnetwork.net","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.65","ipapi Rank":"843","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #843 with 14.65% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS149877","ASN Number":"149877","Network Name":"IJE-AS-ID - PT Integrasi Jaringan Ekosistem","Aliases":"PT. INTEGRASI JARINGAN EKOSISTEM","Provider Family":"weave.co.id","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"22.49","ipapi Rank":"658","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #658 with 22.49% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"ID:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS149878","ASN Number":"149878","Network Name":"IDNIC-CTSOLUSINDO-AS-ID - PT Callysta Total Solusindo","Aliases":"PT. CALLYSTA TOTAL SOLUSINDO","Provider Family":"ctsolusindo.co.id","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.3","ipapi Rank":"966","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #966 with 12.3% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"8","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"8","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"ID:8"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS150170","ASN Number":"150170","Network Name":"WEBELEVEN-AS-AP - Web Eleven","Aliases":"Web Eleven","Provider Family":"web-eleven.com","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.28","ipapi Rank":"908","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #908 with 13.28% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS150493","ASN Number":"150493","Network Name":"IDNIC-PGSS-AS-ID - PT Gunung Sedayu Sentosa","Aliases":"IDNIC PGSS AS ID","Provider Family":"gss.biz.id","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"21.88","ipapi Rank":"660","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #660 with 21.88% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"41","IPsum IPs":"24","IPsum Score >=3":"3","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"39","Talos 2024 IPs":"0","Multi-list IPs":"22","Listed-IP Country Mix":"ID:41"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS150747","ASN Number":"150747","Network Name":"HIRAELECTRONICSANDN-AS-AP - Hire Electronic & Networking","Aliases":"Hire Electronic & Networking","Provider Family":"hiraelectronicsandnetworking.com","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.5","ipapi Rank":"955","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #955 with 12.5% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS150884","ASN Number":"150884","Network Name":"NEWVINA-VN - ANZIX Joint Stock Company","Aliases":"ANZIX Joint Stock Company","Provider Family":"apjii.or.id","RIR Country Code":"VN","Country Name":"Vietnam","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #851 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"VN:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS151148","ASN Number":"151148","Network Name":"TELESAR-AS - Sar Network","Aliases":"Sar Network","Provider Family":"apjii.or.id","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"28.52","ipapi Rank":"592","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #592 with 28.52% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS151595","ASN Number":"151595","Network Name":"IDNIC-MERDEKANET-AS-ID - PT Merdeka Media Teknologi","Aliases":"PT. Merdeka Media Teknologi","Provider Family":"merdekanet.co.id","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.45","ipapi Rank":"851","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #851 with 14.45% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"ID:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS151741","ASN Number":"151741","Network Name":"VORTEX1-AS-IN - VORTEX NETWORKS PRIVATE LIMITED","Aliases":"VORTEX NETWORKS PRIVATE LIMITED","Provider Family":"vortexnetworks.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.99","ipapi Rank":"767","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #767 with 16.99% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS153016","ASN Number":"153016","Network Name":"CHANGEDIGITAL-VN - VN Change Digital Ltd.","Aliases":"VN Change Digital Ltd.","Provider Family":"apjii.or.id","RIR Country Code":"VN","Country Name":"Vietnam","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.41","ipapi Rank":"788","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #788 with 16.41% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS153236","ASN Number":"153236","Network Name":"V3CONECT-AS-IN - KARNATAKA FASTNET PRIVATE LIMITED","Aliases":"KARNATAKA FASTNET PRIVATE LIMITED","Provider Family":"ind.in","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.28","ipapi Rank":"906","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #906 with 13.28% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"4","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"IN:4"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS153307","ASN Number":"153307","Network Name":"BOS-AS-AP - Bangladesh Online Service","Aliases":"Bangladesh Online Service","Provider Family":"bdos.info","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #976 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS153337","ASN Number":"153337","Network Name":"NETRELATION-AS-AP - Net Relation","Aliases":"Net Relation","Provider Family":"netrelationbd.com","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"32.81","ipapi Rank":"571","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #571 with 32.81% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS153490","ASN Number":"153490","Network Name":"DATALINKPLC-AS-AP - DataLink","Aliases":"DataLink","Provider Family":"datalink.com.bd","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.92","ipapi Rank":"691","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #691 with 19.92% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS153844","ASN Number":"153844","Network Name":"RNBL-AS-AP - Riderz Network Broadband (Private) Limited","Aliases":"Riderz Network Broadband (Private) Limit","Provider Family":"riderz.pk","RIR Country Code":"PK","Country Name":"Pakistan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #980 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS154247","ASN Number":"154247","Network Name":"MCO-VN - MCO HA NOI TECHNOLOGY COMPANY LIMITED","Aliases":"MCO HA NOI TECHNOLOGY COMPANY LIMITED","Provider Family":"topserver.vn","RIR Country Code":"VN","Country Name":"Vietnam","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"166","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #166 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"3","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"VN:3"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS154455","ASN Number":"154455","Network Name":"IRINN-AYUSMATI-AS-IN - AYUSHMATI LOGITECH PRIVATE LIMITED","Aliases":"AYUSHMATI LOGITECH PRIVATE LIMITED","Provider Family":"","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.67","ipapi Rank":"890","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #890 with 13.67% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"IN:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS154650","ASN Number":"154650","Network Name":"IRINN-SKYAERO-AS-IN - SKYAERO PRIVATE LIMITED","Aliases":"'-","Provider Family":"","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Unknown","Category":"High-abuse unknown review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #991 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS154676","ASN Number":"154676","Network Name":"EFTETRADINGCORPORATIONLTD-AS-BD - Efte Trading Corporation Ltd","Aliases":"Efte Trading Corporation Ltd","Provider Family":"cloudview.com.bd","RIR Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"apnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"34.77","ipapi Rank":"557","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #557 with 34.77% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS196629","ASN Number":"196629","Network Name":"DOMINION-AS Antipov Oleg","Aliases":"Antipov Oleg","Provider Family":"dominion.ru.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"22.85","ipapi Rank":"652","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #652 with 22.85% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS196767","ASN Number":"196767","Network Name":"INMART1-AS INMART.UA LLC","Aliases":"INMART.UA LLC","Provider Family":"inmart.net.ua","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.91","ipapi Rank":"742","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #742 with 17.91% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS196786","ASN Number":"196786","Network Name":"ASMITEL IP Yashutkin Andrei Vladimirovich","Aliases":"IP Yashutkin Andrei Vladimirovich","Provider Family":"mitel-inter.net","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.43","ipapi Rank":"858","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #858 with 14.43% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS196865","ASN Number":"196865","Network Name":"AIRCOMM Aircomm S.r.L.","Aliases":"Aircomm S.r.L.","Provider Family":"aircomm.it","RIR Country Code":"IT","Country Name":"Italy","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"11.97","ipapi Rank":"987","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #987 with 11.97% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS196886","ASN Number":"196886","Network Name":"Orion-Telekom-Korisnici-AS Orion Telekom Tim d.o.o.Beograd","Aliases":"Orion Telekom Tim d.o.o.Beograd","Provider Family":"oriontelekom.rs","RIR Country Code":"RS","Country Name":"Serbia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.41","ipapi Rank":"791","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #791 with 16.41% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS197052","ASN Number":"197052","Network Name":"YANKOVSKIY-AS Yankovskiy Nikolay Nikolayevich","Aliases":"Yankovskiy Nikolay Nikolayevich","Provider Family":"westcall.spb.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.06","ipapi Rank":"867","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #867 with 14.06% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS197218","ASN Number":"197218","Network Name":"ASLANPRO PP Dmutrashko Evgeny Vitalievich","Aliases":"PP Dmutrashko Evgeny Vitalievich","Provider Family":"","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"45.12","ipapi Rank":"529","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #529 with 45.12% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"12","IPsum IPs":"11","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"UA:12"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS197574","ASN Number":"197574","Network Name":"EXPRESSHOST ExpressHost Ltd","Aliases":"","Provider Family":"ExpressHost Ltd","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Conditional fast-flux ASN seed","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Conditional analytic","Actor / Campaign":"Fast-flux phishing infrastructure","Last Evidence":"2026-09-29","Source IDs":"N38, N01","Evidence Summary":"Conditional fast-flux analytic includes this ASN. This supports source-scoped review, not provider-wide malicious attribution.","Analyst Notes":"Do not enable from this source alone.","Current Community Feed Count":"3","Current Listed IPs":"14","IPsum IPs":"8","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"2","Data-Shield IPs":"8","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"DE:6, PL:5, NL:3"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS197578","ASN Number":"197578","Network Name":"Alekseenko-NET PE Alekseenko Igor Yurevich","Aliases":"PE Alekseenko Igor Yurevich","Provider Family":"pautina-net.ru","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.63","ipapi Rank":"804","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #804 with 15.63% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS197620","ASN Number":"197620","Network Name":"EZ-BIT-AS ezbit sp. z o.o.","Aliases":"ezbit sp. z o.o.","Provider Family":"ezbit.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.26","ipapi Rank":"968","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #968 with 12.26% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS197697","ASN Number":"197697","Network Name":"PL-LUB-DERKOM-AS Dariusz Klimczuk trading as DERKOM Sp. J.","Aliases":"Dariusz Klimczuk trading as DERKOM Sp. J","Provider Family":"derkom.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"27.27","ipapi Rank":"602","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #602 with 27.27% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"PL:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS197714","ASN Number":"197714","Network Name":"CITYLINE-RU Chishko Evgeniy Nikolaevich","Aliases":"Chishko Evgeniy Nikolaevich","Provider Family":"","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.48","ipapi Rank":"898","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #898 with 13.48% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS197793","ASN Number":"197793","Network Name":"GIGABIT-NET Gigabit LLC","Aliases":"Gigabit LLC","Provider Family":"ggbt.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.75","ipapi Rank":"718","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #718 with 18.75% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS197835","ASN Number":"197835","Network Name":"FUSOLAB FUSOLAB APS E ASD","Aliases":"Fusolab onlus","Provider Family":"ninux.org","RIR Country Code":"IT","Country Name":"Italy","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.28","ipapi Rank":"912","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #912 with 13.28% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"2","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"IT:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS197868","ASN Number":"197868","Network Name":"ServiceTelecom LLC Service Telecom","Aliases":"LLC Service Telecom","Provider Family":"service-net.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.7","ipapi Rank":"947","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #947 with 12.7% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"RU:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS197893","ASN Number":"197893","Network Name":"ELSUHD-AS Elsuhd Company for Communications Services, Cybersecurity, Information Technology, Electronic Governance, and Commercial Agencies, Ltd.","Aliases":"Elsuhd Company for Communications Servic","Provider Family":"elsuhdnet.com","RIR Country Code":"IQ","Country Name":"Iraq","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.14","ipapi Rank":"708","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #708 with 19.14% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS197960","ASN Number":"197960","Network Name":"MEGANET LIMITED LIABILITY COMPANY \"INTERNET SERVICE PROVIDER \"MEGA\"","Aliases":"LIMITED LIABILITY COMPANY INTERNET SERVI","Provider Family":"mega.net.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"21.03","ipapi Rank":"676","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #676 with 21.03% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"12","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"11","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"UA:12"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS198075","ASN Number":"198075","Network Name":"BOUNCEZERO-MNT BounceZero Ltd","Aliases":"BounceZero Ltd","Provider Family":"bouncezero.io","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"42.58","ipapi Rank":"535","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #535 with 42.58% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS198158","ASN Number":"198158","Network Name":"AGNET-AS FIRMA USLUGOWO-HANDLOWA \"AG-net\" JOANNA MACZENSKA","Aliases":"FIRMA USLUGOWO-HANDLOWA AG-net JOANNA MA","Provider Family":"meganet.com.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"61.33","ipapi Rank":"490","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #490 with 61.33% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"PL:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS198364","ASN Number":"198364","Network Name":"BANATSYNC SRL","Aliases":"","Provider Family":"banatsync.com","RIR Country Code":"RO","Country Name":"Romania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Current abuse-concentration hosting review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.76","ipapi Rank":"944","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #944 with 12.76% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Vendor concentration is a prioritization signal, not malicious-login probability or provider complicity.","Current Community Feed Count":"2","Current Listed IPs":"257","IPsum IPs":"257","IPsum Score >=3":"96","IPsum Score >=5":"38","Open-Proxy IPs":"0","Data-Shield IPs":"134","Talos 2024 IPs":"0","Multi-list IPs":"134","Listed-IP Country Mix":"FR:257"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS198401","ASN Number":"198401","Network Name":"GECKONET-AS Geckonet Sp. z o. o.","Aliases":"Geckonet Sp. z o. o.","Provider Family":"geckonet.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"32.16","ipapi Rank":"573","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #573 with 32.16% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS198418","ASN Number":"198418","Network Name":"CELcom CELCOM SPOLKA Z OGRANICZONA ODPOWIEDZIALNOSCIA","Aliases":"CELCOM SPOLKA Z OGRANICZONA ODPOWIEDZIAL","Provider Family":"celcom.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"46.64","ipapi Rank":"528","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #528 with 46.64% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS198525","ASN Number":"198525","Network Name":"CLIMAX-AS ClimaxNET sp. z o.o.","Aliases":"ClimaxNET sp. z o.o.","Provider Family":"climaxnet.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"99.22","ipapi Rank":"463","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #463 with 99.22% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS198550","ASN Number":"198550","Network Name":"nodehost-as NODE HOST LIMITED","Aliases":"","Provider Family":"NODE HOST LIMITED","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Conditional fast-flux ASN seed","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Conditional analytic","Actor / Campaign":"Fast-flux phishing infrastructure","Last Evidence":"2026-09-29","Source IDs":"N38, N01","Evidence Summary":"Conditional fast-flux analytic includes this ASN. This supports source-scoped review, not provider-wide malicious attribution.","Analyst Notes":"Do not enable from this source alone.","Current Community Feed Count":"3","Current Listed IPs":"13","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"4","Data-Shield IPs":"8","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"SE:4, DE:3, NL:3, PL:3"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS198793","ASN Number":"198793","Network Name":"Benda IP Benda Artyom Sergeevich","Aliases":"IP Benda Artyom Sergeevich","Provider Family":"","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.06","ipapi Rank":"868","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #868 with 14.06% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS198910","ASN Number":"198910","Network Name":"NETPAK-AS NETPAK Sp. z o.o","Aliases":"NETPAK Sp. z o.o","Provider Family":"netpak.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.19","ipapi Rank":"761","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #761 with 17.19% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS199099","ASN Number":"199099","Network Name":"ERLION ERLION BILISIM LIMITED SIRKETI","Aliases":"ERLION BILISIM LIMITED SIRKETI","Provider Family":"erlion.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"50","ipapi Rank":"512","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #512 with 50% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS199929","ASN Number":"199929","Network Name":"emircanapak-hostvera Emircan Apak","Aliases":"Emircan Apak","Provider Family":"bogahost.com","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.3","ipapi Rank":"701","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #701 with 19.3% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"TR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS200192","ASN Number":"200192","Network Name":"Super-Optik Super Optik Tech LLC","Aliases":"Super Optik Tech LLC","Provider Family":"superoptic.net","RIR Country Code":"AZ","Country Name":"Azerbaijan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"26.95","ipapi Rank":"603","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #603 with 26.95% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"2","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"AZ:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS200203","ASN Number":"200203","Network Name":"DATABRIDGE GLOBAL DATA BRIDGE INTERNATIONAL LIMITED","Aliases":"GLOBAL DATA BRIDGE INTERNATIONAL LIMITED","Provider Family":"databridge.international","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Government","Category":"High-abuse government review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"27.47","ipapi Rank":"598","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this government ASN #598 with 27.47% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS200391","ASN Number":"200391","Network Name":"KREZ999AS KREZ 999 EOOD","Aliases":"KREZ 999 EOOD","Provider Family":"fasthost.ltd","RIR Country Code":"BG","Country Name":"Bulgaria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.23","ipapi Rank":"812","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #812 with 15.23% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"8","IPsum IPs":"4","IPsum Score >=3":"2","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"7","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"US:8"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS200404","ASN Number":"200404","Network Name":"JETNET Jetnet Telekom Int. Bil.Hiz. San and Tic. LTD","Aliases":"Jetnet Telekom Int. Bil.Hiz. San and Tic","Provider Family":"jetnetinternet.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"66.41","ipapi Rank":"483","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #483 with 66.41% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS200582","ASN Number":"200582","Network Name":"ORG-LO31-RIPE LLC O-NET","Aliases":"LLC O-NET","Provider Family":"o-net.com.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.09","ipapi Rank":"920","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #920 with 13.09% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"UA:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS200750","ASN Number":"200750","Network Name":"KLIKOM_NET Klikom.net Sp.z o.o.","Aliases":"Klikom.net Sp.z o.o.","Provider Family":"klikom.net","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"80.95","ipapi Rank":"473","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #473 with 80.95% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"PL:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS200814","ASN Number":"200814","Network Name":"GAZIKNET LIMNET , LLC","Aliases":"LIMNET, LLC","Provider Family":"limnet.com.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.88","ipapi Rank":"715","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #715 with 18.88% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"6","IPsum IPs":"4","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"5","Talos 2024 IPs":"0","Multi-list IPs":"3","Listed-IP Country Mix":"UA:6"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS201030","ASN Number":"201030","Network Name":"hostgeb-asn HOSTGEB BILISIM TEKNOLOJILERI SANAYI VE TICARET LIMITED SIRKETI","Aliases":"HOSTGEB BILISIM TEKNOLOJILERI SANAYI VE","Provider Family":"nurullah.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"26.56","ipapi Rank":"607","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #607 with 26.56% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS201132","ASN Number":"201132","Network Name":"MSCode Mateusz Sikorski trading as MSCode","Aliases":"Mateusz Sikorski trading as MSCode","Provider Family":"mscode.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.89","ipapi Rank":"931","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #931 with 12.89% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS201151","ASN Number":"201151","Network Name":"intermax InterMAX Regional Networks LLC","Aliases":"InterMAX Regional Networks LLC","Provider Family":"intermax.net.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"22.56","ipapi Rank":"657","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #657 with 22.56% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS201219","ASN Number":"201219","Network Name":"VSD Mushegh Baghdasaryan","Aliases":"Mushegh Baghdasaryan","Provider Family":"vcd.am","RIR Country Code":"AM","Country Name":"Armenia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"30.86","ipapi Rank":"581","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #581 with 30.86% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS201667","ASN Number":"201667","Network Name":"ASMBP LLC","Aliases":"","Provider Family":"ipxo.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Current abuse-concentration hosting review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"47.75","ipapi Rank":"525","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #525 with 47.75% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Vendor concentration is a prioritization signal, not malicious-login probability or provider complicity.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS201884","ASN Number":"201884","Network Name":"am-ispsupport ISP SUPPORT LLC","Aliases":"ISP SUPPORT LLC","Provider Family":"ispsupport.am","RIR Country Code":"AM","Country Name":"Armenia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.64","ipapi Rank":"778","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #778 with 16.64% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"4","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"AM:4"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS202375","ASN Number":"202375","Network Name":"DIGITALBOX Digital Albox SL","Aliases":"Digital Albox SL","Provider Family":"","RIR Country Code":"ES","Country Name":"Spain","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.1","ipapi Rank":"734","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #734 with 18.1% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"3","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"ES:3"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS203003","ASN Number":"203003","Network Name":"Magna Capax Finland Oy","Aliases":"","Provider Family":"magnacapax.fi","RIR Country Code":"FI","Country Name":"Finland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Current abuse-concentration hosting review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.91","ipapi Rank":"743","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #743 with 17.91% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Vendor concentration is a prioritization signal, not malicious-login probability or provider complicity.","Current Community Feed Count":"1","Current Listed IPs":"7","IPsum IPs":"7","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"FI:7"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS203140","ASN Number":"203140","Network Name":"NETUS NETUS Renata Gieruszczak-Fikus","Aliases":"NETUS Renata Gieruszczak-Fikus","Provider Family":"netusinternet.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.97","ipapi Rank":"924","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #924 with 12.97% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS203320","ASN Number":"203320","Network Name":"TURIEN-AS Turien en Co. Assuradeuren B.V.","Aliases":"Turien en Co. Assuradeuren B.V.","Provider Family":"turien.nl","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Banking","Category":"High-abuse banking review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.41","ipapi Rank":"785","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this banking ASN #785 with 16.41% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS203565","ASN Number":"203565","Network Name":"VRLAN-NET PE Gumenova Olga","Aliases":"PE Gumenova Olga","Provider Family":"vrlan.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.89","ipapi Rank":"934","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #934 with 12.89% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS203667","ASN Number":"203667","Network Name":"zipnet ZIPnet sp. z o.o.","Aliases":"ZIPnet sp. z o.o.","Provider Family":"zipnet.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #783 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS204144","ASN Number":"204144","Network Name":"COMFORT-AS Comfort XXI Century Ltd.","Aliases":"Comfort XXI Century Ltd.","Provider Family":"komfort21vek.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.86","ipapi Rank":"769","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #769 with 16.86% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"9","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"9","Talos 2024 IPs":"0","Multi-list IPs":"3","Listed-IP Country Mix":"RU:9"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS204208","ASN Number":"204208","Network Name":"Peravix Group LTD","Aliases":"","Provider Family":"peravix.co.uk","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Current abuse-concentration hosting review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"50","ipapi Rank":"515","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #515 with 50% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Vendor concentration is a prioritization signal, not malicious-login probability or provider complicity.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS204685","ASN Number":"204685","Network Name":"MGN PE KRYVENKO SERGIY ANDRIYOVYCH","Aliases":"PE KRYVENKO SERGIY ANDRIYOVYCH","Provider Family":"","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"25.39","ipapi Rank":"620","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #620 with 25.39% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"8","IPsum IPs":"3","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"7","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"UA:8"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS205100","ASN Number":"205100","Network Name":"F3NETZE F3 Netze e.V.","Aliases":"F3 Netze e.V.","Provider Family":"f3netze.de","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.89","ipapi Rank":"936","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #936 with 12.89% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"16","IPsum IPs":"16","IPsum Score >=3":"2","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"16","Talos 2024 IPs":"15","Multi-list IPs":"16","Listed-IP Country Mix":"DE:16"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS205146","ASN Number":"205146","Network Name":"avanet-as Bartlomiej Michal Czyz trading as F.P.H.U AVANET","Aliases":"Bartlomiej Michal Czyz trading as F.P.H.","Provider Family":"avanet.net.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"64.32","ipapi Rank":"485","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #485 with 64.32% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS205463","ASN Number":"205463","Network Name":"VDSGLOBAL Pembe Gul Isguzar Karagoz","Aliases":"Pembe Gul Isguzar Karagoz","Provider Family":"vdsmerkezi.com","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"55.41","ipapi Rank":"499","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #499 with 55.41% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"6","IPsum IPs":"4","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"2","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"TR:6"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS205872","ASN Number":"205872","Network Name":"EXTRANET-AS EXTRANET 2010","Aliases":"EXTRANET 2010","Provider Family":"exstranet.bg","RIR Country Code":"BG","Country Name":"Bulgaria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.27","ipapi Rank":"703","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #703 with 19.27% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS205980","ASN Number":"205980","Network Name":"WD-Corp W&D CORP - FZCO","Aliases":"W&D CORP - FZCO","Provider Family":"","RIR Country Code":"AE","Country Name":"United Arab Emirates","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"39.45","ipapi Rank":"540","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #540 with 39.45% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS206069","ASN Number":"206069","Network Name":"Cornseed Limited","Aliases":"","Provider Family":"ipxo.com","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting","Category":"Current abuse-concentration hosting review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.42","ipapi Rank":"754","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #754 with 17.42% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Vendor concentration is a prioritization signal, not malicious-login probability or provider complicity.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS206092","ASN Number":"206092","Network Name":"SECFIREWALLAS F.N.S. HOLDINGS LIMITED","Aliases":"F.N.S. HOLDINGS LIMITED","Provider Family":"fns-holdings.com","RIR Country Code":"CY","Country Name":"Cyprus","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"20.6","ipapi Rank":"680","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #680 with 20.6% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"885","IPsum IPs":"422","IPsum Score >=3":"2","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"700","Talos 2024 IPs":"0","Multi-list IPs":"237","Listed-IP Country Mix":"US:439, SG:315, GB:28, FR:23, PL:20, BR:14, SE:14, CH:11"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS206388","ASN Number":"206388","Network Name":"ertebatatazinkia Gostaresh Ertebat Azin Kia Company PJSC","Aliases":"Gostaresh Ertebat Azin Kia Company","Provider Family":"","RIR Country Code":"IR","Country Name":"Iran","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.85","ipapi Rank":"938","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #938 with 12.85% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"6","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"6","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"IR:6"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS206680","ASN Number":"206680","Network Name":"PG19-Rovenki Consumer Internet Cooperative PG-19","Aliases":"Consumer Internet Cooperative PG-19","Provider Family":"pg19.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"25","ipapi Rank":"623","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #623 with 25% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS206803","ASN Number":"206803","Network Name":"asterabit LLC Terabit","Aliases":"LLC Terabit","Provider Family":"terabitvu.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.21","ipapi Rank":"794","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #794 with 16.21% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS206813","ASN Number":"206813","Network Name":"AS4830org 4830.org e. V.","Aliases":"4830.org e. V.","Provider Family":"4830.org","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"26.66","ipapi Rank":"606","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #606 with 26.66% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"256","IPsum IPs":"256","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"DE:256"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS207423","ASN Number":"207423","Network Name":"STEILSOUTH-AS STEIL-SOUTH LTD","Aliases":"STEIL-SOUTH LTD","Provider Family":"stl-u.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"49.09","ipapi Rank":"522","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #522 with 49.09% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RU:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS207461","ASN Number":"207461","Network Name":"host-industry HOSTING INDUSTRY LIMITED","Aliases":"","Provider Family":"HOSTING INDUSTRY LIMITED","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Point-IOC provider context","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Exact-IP context","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"N41, N01","Evidence Summary":"Current origin of repeated Settra MeshAgent C2 endpoint 193.5.65.114. This supports source-scoped review, not provider-wide malicious attribution.","Analyst Notes":"Independent current abuse concentration or direct successful sign-in campaign evidence required for ASN-wide alert escalation","Current Community Feed Count":"3","Current Listed IPs":"5","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"UA:3, DE:1, US:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS207462","ASN Number":"207462","Network Name":"LuxeNetwork Al-Jeel Al-Sabei Internet Services Co., Ltd","Aliases":"Al-Jeel Al-Sabei Internet Services","Provider Family":"","RIR Country Code":"IQ","Country Name":"Iraq","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"25.98","ipapi Rank":"612","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #612 with 25.98% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS207475","ASN Number":"207475","Network Name":"RLAN FOP Onuschak Oleg Volodimirovich","Aliases":"FOP Onuschak Oleg Volodimirovich","Provider Family":"astra.in.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.02","ipapi Rank":"921","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #921 with 13.02% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"UA:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS207483","ASN Number":"207483","Network Name":"NETVIA Netvia Bilisim Yazilim Dan. Tic. Ltd. Sti.","Aliases":"Netvia Bilisim Yazilim Dan. Tic. Ltd. St","Provider Family":"netvia.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"72.48","ipapi Rank":"477","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #477 with 72.48% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"TR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS207830","ASN Number":"207830","Network Name":"LIMNET LIMNET , LLC","Aliases":"LIMNET, LLC","Provider Family":"limnet.com.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"22.66","ipapi Rank":"655","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #655 with 22.66% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS208142","ASN Number":"208142","Network Name":"Rocket-Telecom-AS LLC Rocket Telecom","Aliases":"LLC Rocket Telecom","Provider Family":"rocketcom.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"34.71","ipapi Rank":"558","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #558 with 34.71% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RU:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS208314","ASN Number":"208314","Network Name":"ACCESSTELECOM Access Telecom Ltd.","Aliases":"Access Telecom Ltd.","Provider Family":"access52.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"11.98","ipapi Rank":"986","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #986 with 11.98% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"4","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"4","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"RU:4"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS208323","ASN Number":"208323","Network Name":"APPLIEDPRIVACY-AS Foundation for Applied Privacy","Aliases":"Foundation for Applied Privacy","Provider Family":"appliedprivacy.net","RIR Country Code":"AT","Country Name":"Austria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"38.28","ipapi Rank":"544","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #544 with 38.28% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"22","IPsum IPs":"19","IPsum Score >=3":"7","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"15","Talos 2024 IPs":"6","Multi-list IPs":"15","Listed-IP Country Mix":"AT:22"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS208356","ASN Number":"208356","Network Name":"SmartCities-AS Smart Cities Limited Liability Partnership","Aliases":"Smart Cities Limited Liability Partnersh","Provider Family":"scity.pro","RIR Country Code":"KZ","Country Name":"Kazakhstan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"28.52","ipapi Rank":"593","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #593 with 28.52% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS208752","ASN Number":"208752","Network Name":"BaykonurSvyazInform-AS \"BaykonurSvyazInform\" SUE","Aliases":"BaykonurSvyazInform SUE","Provider Family":"baykonur.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.23","ipapi Rank":"822","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #822 with 15.23% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS208803","ASN Number":"208803","Network Name":"ACN ACN LLC","Aliases":"ACN LLC","Provider Family":"acn.group","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.41","ipapi Rank":"725","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #725 with 18.41% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS208843","ASN Number":"208843","Network Name":"ALPHASTRIKE-RESEARCH Alpha Strike Labs GmbH","Aliases":"Alpha Strike Labs GmbH","Provider Family":"alphastrike.io","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"62.5","ipapi Rank":"486","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #486 with 62.5% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"269","IPsum IPs":"269","IPsum Score >=3":"27","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"254","Talos 2024 IPs":"0","Multi-list IPs":"254","Listed-IP Country Mix":"DE:269"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS209078","ASN Number":"209078","Network Name":"AT-AS AMUDARYO TONER LLC","Aliases":"AMUDARYO TONER LLC","Provider Family":"","RIR Country Code":"UZ","Country Name":"Uzbekistan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"28.91","ipapi Rank":"590","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #590 with 28.91% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS209219","ASN Number":"209219","Network Name":"asdin LLC Daginfonet","Aliases":"LLC Daginfonet","Provider Family":"daginfonet.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.48","ipapi Rank":"752","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #752 with 17.48% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"RU:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS209262","ASN Number":"209262","Network Name":"GSLine GSLINE LLC","Aliases":"GSLINE LLC","Provider Family":"","RIR Country Code":"AM","Country Name":"Armenia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.45","ipapi Rank":"857","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #857 with 14.45% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS209275","ASN Number":"209275","Network Name":"NetMax NETMAX TELEKOMUNIKASYON ILETISIM HIZMETLERI TICARET LIMITED SIRKETI","Aliases":"NETMAX TELEKOMUNIKASYON ILETISIM HIZMETL","Provider Family":"netmax.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"34.77","ipapi Rank":"556","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #556 with 34.77% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS209334","ASN Number":"209334","Network Name":"MODAT-01 Modat B.V.","Aliases":"Modat B.V.","Provider Family":"modat.io","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"22.66","ipapi Rank":"653","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #653 with 22.66% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"351","IPsum IPs":"351","IPsum Score >=3":"77","IPsum Score >=5":"55","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"CA:256, FR:52, SG:43"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS209353","ASN Number":"209353","Network Name":"LABEL Maurizio Giuseppe Fanari trading as LABEL SISTEMI TECNOLOGICI","Aliases":"Maurizio Giuseppe Fanari trading as LABE","Provider Family":"fastweb.it","RIR Country Code":"IT","Country Name":"Italy","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"26.46","ipapi Rank":"610","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #610 with 26.46% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"21","IPsum IPs":"21","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"IT:21"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS209378","ASN Number":"209378","Network Name":"INIOS-AS Inios Oy","Aliases":"","Provider Family":"Inios Oy","RIR Country Code":"FI","Country Name":"Finland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Conditional fast-flux ASN seed","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Conditional analytic","Actor / Campaign":"Fast-flux phishing infrastructure","Last Evidence":"2026-09-29","Source IDs":"N38, N01","Evidence Summary":"Conditional fast-flux analytic includes this ASN. This supports source-scoped review, not provider-wide malicious attribution.","Analyst Notes":"Do not enable from this source alone.","Current Community Feed Count":"2","Current Listed IPs":"7","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"6","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"FI:7"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS209937","ASN Number":"209937","Network Name":"ASKUBTELE Kub-Telecom Ltd.","Aliases":"Kub-Telecom Ltd.","Provider Family":"","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"27.34","ipapi Rank":"601","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #601 with 27.34% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"UA:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS210067","ASN Number":"210067","Network Name":"SKYLINE-AS Chayka Vladimir","Aliases":"Chayka Vladimir","Provider Family":"","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.89","ipapi Rank":"935","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #935 with 12.89% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS210135","ASN Number":"210135","Network Name":"YUG-TELECOM-K-AS Yug-Telecom-K Ltd.","Aliases":"Yug-Telecom-K Ltd.","Provider Family":"omicron.online","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.79","ipapi Rank":"717","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #717 with 18.79% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"RU:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS210238","ASN Number":"210238","Network Name":"Dieffeitalia Dieffeitalia.it S.r.l.","Aliases":"Dieffeitalia.it S.r.l.","Provider Family":"dieffeitalia.it","RIR Country Code":"IT","Country Name":"Italy","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.14","ipapi Rank":"763","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #763 with 17.14% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"32","IPsum IPs":"22","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"14","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"IT:32"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS210557","ASN Number":"210557","Network Name":"FalakNET Houeiss and AI-Othman Internet Services LLC","Aliases":"Houeiss and AI-Othman Internet Services","Provider Family":"falaknet.online","RIR Country Code":"SY","Country Name":"Syria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"35.55","ipapi Rank":"555","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #555 with 35.55% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS210634","ASN Number":"210634","Network Name":"YSTRONTEK-NETWORKS Suzhou Yesong Information Technology Co., Ltd.","Aliases":"Suzhou Yesong Information Technology Co.","Provider Family":"yesongit.com","RIR Country Code":"CN","Country Name":"China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.88","ipapi Rank":"713","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #713 with 18.88% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS210743","ASN Number":"210743","Network Name":"BABBAR-AS BABBAR SAS","Aliases":"Babbar SAS","Provider Family":"babbar.tech","RIR Country Code":"FR","Country Name":"France","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"53.13","ipapi Rank":"503","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #503 with 53.13% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"509","IPsum IPs":"509","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"12","Talos 2024 IPs":"0","Multi-list IPs":"12","Listed-IP Country Mix":"FR:509"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS210949","ASN Number":"210949","Network Name":"SanalSantral SANAL SANTRAL TELEKOMUNIKASYON TICARET ANONIM SIRKETI","Aliases":"SANAL SANTRAL TELEKOMUNIKASYON TICARET A","Provider Family":"sanalsantral.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #867 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS211190","ASN Number":"211190","Network Name":"QUICKNET QUICKNET LLC","Aliases":"QUICKNET LLC","Provider Family":"","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.54","ipapi Rank":"808","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #808 with 15.54% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"3","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"UA:3"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS211212","ASN Number":"211212","Network Name":"GBD-AS GBD Software as a Service Private Limited Company","Aliases":"GBD Software as a Service Private Limite","Provider Family":"gbd.hu","RIR Country Code":"HU","Country Name":"Hungary","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"24.9","ipapi Rank":"625","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #625 with 24.9% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS211250","ASN Number":"211250","Network Name":"TELECOMTRADE-UA-AS TELECOM TRADE LLC","Aliases":"TELECOM TRADE LLC","Provider Family":"westele.com.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"28.32","ipapi Rank":"594","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #594 with 28.32% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS211298","ASN Number":"211298","Network Name":"DRIFTNET Driftnet Ltd","Aliases":"Driftnet Ltd","Provider Family":"driftnet.io","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"130","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #130 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"1012","IPsum IPs":"1012","IPsum Score >=3":"378","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1009","Talos 2024 IPs":"0","Multi-list IPs":"1009","Listed-IP Country Mix":"GB:774, IR:238"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS211496","ASN Number":"211496","Network Name":"surnet-gete SURNET ILETISIM TEKNOLOJI TIC VE SAN LTD STI","Aliases":"SURNET ILETISIM TEKNOLOJI TIC VE SAN LTD","Provider Family":"surnet.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"51.04","ipapi Rank":"507","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #507 with 51.04% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"TR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS211504","ASN Number":"211504","Network Name":"AN-TV STUDIO AN-TV SRL","Aliases":"STUDIO AN-TV SRL","Provider Family":"","RIR Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.5","ipapi Rank":"957","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #957 with 12.5% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"4","IPsum IPs":"2","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"MD:4"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS211560","ASN Number":"211560","Network Name":"UGUR-OZTURK Datafex Bilisim Teknolojileri Ticaret Limited Sirketi","Aliases":"Datafex Bilisim Teknolojileri Ticaret Li","Provider Family":"datafex.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.84","ipapi Rank":"834","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #834 with 14.84% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS211590","ASN Number":"211590","Network Name":"BUCKLOG Bucklog SARL","Aliases":"Bucklog SARL","Provider Family":"tutamail.com","RIR Country Code":"FR","Country Name":"France","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"50.78","ipapi Rank":"509","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #509 with 50.78% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"33","IPsum IPs":"33","IPsum Score >=3":"15","IPsum Score >=5":"9","Open-Proxy IPs":"0","Data-Shield IPs":"31","Talos 2024 IPs":"0","Multi-list IPs":"31","Listed-IP Country Mix":"FR:33"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS211680","ASN Number":"211680","Network Name":"AS-BITSIGHT NSEC - Sistemas Informaticos, S.A.","Aliases":"NSEC - Sistemas Informaticos, S.A.","Provider Family":"bitsight.com","RIR Country Code":"PT","Country Name":"Portugal","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"55.27","ipapi Rank":"500","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #500 with 55.27% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"275","IPsum IPs":"275","IPsum Score >=3":"127","IPsum Score >=5":"10","Open-Proxy IPs":"0","Data-Shield IPs":"219","Talos 2024 IPs":"0","Multi-list IPs":"219","Listed-IP Country Mix":"NL:145, US:130"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS211851","ASN Number":"211851","Network Name":"WEB9 SECKIN CAN CELENK trading as Web9 Bilisim ve Yazilim Hizmetleri","Aliases":"SECKIN CAN CELENK trading as Web9 Bilisi","Provider Family":"w9.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the Very High band at rank #607 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"TR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS211947","ASN Number":"211947","Network Name":"KREMEN-IX PP Vizit-Service","Aliases":"PP Vizit-Service","Provider Family":"vizit-net.com","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"32.03","ipapi Rank":"574","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #574 with 32.03% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"UA:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS211995","ASN Number":"211995","Network Name":"a2z A2Z Technologies CJSC","Aliases":"A2Z Technologies CJSC","Provider Family":"a2z.az","RIR Country Code":"AZ","Country Name":"Azerbaijan","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.49","ipapi Rank":"847","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #847 with 14.49% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"AZ:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS212193","ASN Number":"212193","Network Name":"vivanet VIVA INTERNET LIMITED SIRKETI","Aliases":"VIVA INTERNET LIMITED SIRKETI","Provider Family":"vivanet.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"99.61","ipapi Rank":"458","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #458 with 99.61% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"TR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS212280","ASN Number":"212280","Network Name":"AS212280-Storm Storm for Information Technology, Internet Services, Communications, Electronic Solutions, Software, and Automation LLC","Aliases":"Storm for Information Technology, Intern","Provider Family":"stormnetwork.net","RIR Country Code":"IQ","Country Name":"Iraq","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.72","ipapi Rank":"946","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #946 with 12.72% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"2","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"2","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"IQ:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS212285","ASN Number":"212285","Network Name":"Linyitnet Linyit Net Telekomunikasyon Hizmetleri Sanayi ve Ticaret Ltd. Sti.","Aliases":"Linyit Net Telekomunikasyon Hizmetleri S","Provider Family":"linyitnet.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"26.56","ipapi Rank":"608","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #608 with 26.56% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS212432","ASN Number":"212432","Network Name":"SOYUZNET-AS Zishko Alexandr","Aliases":"Zishko Alexandr","Provider Family":"soyuznet.com.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.84","ipapi Rank":"835","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #835 with 14.84% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS212463","ASN Number":"212463","Network Name":"NGroup FOP Polischyk O.V","Aliases":"FOP Polischyk O.V","Provider Family":"netgroup.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.23","ipapi Rank":"814","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #814 with 15.23% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"2","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"UA:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS212617","ASN Number":"212617","Network Name":"ALDEN-AS Lynnyk Olexii","Aliases":"Lynnyk Olexii","Provider Family":"","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.53","ipapi Rank":"699","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #699 with 19.53% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"10","IPsum IPs":"3","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"10","Talos 2024 IPs":"0","Multi-list IPs":"3","Listed-IP Country Mix":"UA:10"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS212623","ASN Number":"212623","Network Name":"NYSANET-AS NysaNet sp. z o.o.","Aliases":"NysaNet sp. z o.o.","Provider Family":"nysanet.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"170","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #170 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS212641","ASN Number":"212641","Network Name":"INCOM Incom Net Ltd","Aliases":"Incom Net Ltd","Provider Family":"","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.04","ipapi Rank":"828","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #828 with 15.04% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS212695","ASN Number":"212695","Network Name":"LTS-AS Link Telecom Service Ltd","Aliases":"Link Telecom Service Ltd","Provider Family":"lts.org.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"21.09","ipapi Rank":"675","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #675 with 21.09% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS212825","ASN Number":"212825","Network Name":"NIMNET-AS Novitni Informaciini Merezhi Ltd","Aliases":"Novitni Informaciini Merezhi Ltd","Provider Family":"nim-net.com.ua","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #895 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS213252","ASN Number":"213252","Network Name":"CENUTA Cenuta Telekomunikasyon Anonim Sirketi","Aliases":"Cenuta Telekomunikasyon Anonim Sirketi","Provider Family":"cenuta.com","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"52.54","ipapi Rank":"504","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #504 with 52.54% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS213404","ASN Number":"213404","Network Name":"YstronTek-Networks Suzhou Yesong Information Technology Co., Ltd.","Aliases":"Suzhou Yesong Information Technology Co.","Provider Family":"yesongit.com","RIR Country Code":"CN","Country Name":"China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"43.55","ipapi Rank":"533","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #533 with 43.55% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS213412","ASN Number":"213412","Network Name":"ONYPHE ONYPHE SAS","Aliases":"ONYPHE SAS","Provider Family":"onyphe.io","RIR Country Code":"FR","Country Name":"France","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"134","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #134 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1048","IPsum IPs":"1048","IPsum Score >=3":"347","IPsum Score >=5":"1","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"FR:492, US:492, CN:64"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS213461","ASN Number":"213461","Network Name":"NorthernLightsCloud Igor Andreevich Nemtsov","Aliases":"Igor Andreevich Nemtsov","Provider Family":"comfortel.pro","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.92","ipapi Rank":"692","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #692 with 19.92% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"SE:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS213474","ASN Number":"213474","Network Name":"Reserved ASN with active origin observed (former HOMELINE-AS HomeLine Broadband LLC)","Aliases":"HomeLine Broadband LLC; HOMELINE-AS; HOMELINE-AS HomeLine Broadband LLC","Provider Family":"whitelabel.sh","RIR Country Code":"ZZ","Country Name":"Unknown","Geography Scope":"Unknown","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"reserved","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Former ASN-DROP; registration and routing anomaly","Evidence Level":"Historical / lifecycle","FP Risk":"Very High","Recommended Use":"Disabled by default. Retain history and review current assignment, origin, and exact indicators before any enforcement.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01","Evidence Summary":"Present in the 2026-09-15 ASN-DROP snapshot and absent from the 2026-09-29 snapshot; delisting does not establish benignness.","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. Current RIR and routing state require lifecycle review.","Current Community Feed Count":"2","Current Listed IPs":"257","IPsum IPs":"257","IPsum Score >=3":"5","IPsum Score >=5":"2","Open-Proxy IPs":"0","Data-Shield IPs":"14","Talos 2024 IPs":"0","Multi-list IPs":"14","Listed-IP Country Mix":"FR:256, FI:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS213498","ASN Number":"213498","Network Name":"INFRONET-AS Infronet-Telecom LLC","Aliases":"Infronet-Telecom LLC","Provider Family":"infronet.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.89","ipapi Rank":"933","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #933 with 12.89% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS213511","ASN Number":"213511","Network Name":"VSVK VSVK Onderhoud B.V.","Aliases":"VSVK; fraudulent RIPE identity; Railnet-linked; vonie.net; VSVK Onderhoud B.V. (fraudulently impersonated; historical)","Provider Family":"VSVK","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2025-09-15","Network Type":"Bulletproof / high-risk hosting family","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"High","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"414","Login / Identity Evidence":"No","Actor / Campaign":"malicious infrastructure registration; Railnet ecosystem","Last Evidence":"2026-09-29","Source IDs":"S01, S02, X031, N01, S03","Evidence Summary":"Recorded Future found that AS213511 used the identity of an unrelated Dutch construction company and operated through the Railnet ecosystem; the legitimate VSVK business denied involvement. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as VSVK (vonie.net).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. High for fraudulent historical registration; that is not evidence against the impersonated legitimate company. Not announcing routes on 2026-09-15, though the ASN remains in the current Spamhaus ASN-DROP feed. Do not label the impersonated company malicious. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS213694","ASN Number":"213694","Network Name":"INLAN-AS INLAN LLC","Aliases":"INLAN LLC","Provider Family":"","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #985 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"3","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"RU:3"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS213884","ASN Number":"213884","Network Name":"FAST-FIBER Reynaldo Papahan trading as FAST-FIBER NETWORK AND DATA SOLUTION","Aliases":"Reynaldo Papahan trading as FAST-FIBER N","Provider Family":"fast-fiber.com.ph","RIR Country Code":"PH","Country Name":"Philippines","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"22.66","ipapi Rank":"656","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #656 with 22.66% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS213999","ASN Number":"213999","Network Name":"THE-CLIENTS WorkTitans B.V.","Aliases":"THE.Hosting clients; Stark Industries-linked; THE-CLIENTS; WorkTitans B.V.; THE-CLIENTS (historical/current registry label)","Provider Family":"THE.Hosting clients","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Not currently originating","Route Last Seen":"2026-07-30","Network Type":"Bulletproof / high-risk hosting family","Category":"Unannounced or low-visibility ASN retained for review","Evidence Level":"High","FP Risk":"N/A","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Spamhaus ASN-DROP":"Yes","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"416","Login / Identity Evidence":"No","Actor / Campaign":"Stark/PQ.Hosting/THE.Hosting infrastructure","Last Evidence":"2026-09-29","Source IDs":"S01, S02, N01, S03","Evidence Summary":"The 2026-09-15 Spamhaus ASN-DROP feed associates AS213999 with stark-industries.solutions. This is a current block-oriented source signal, but no independent provider-level campaign attribution was established in this review. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as THE-CLIENTS (stark-industries.solutions).","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious. High for current feed inclusion; medium for analytical attribution because this row relies on the live feed rather than a detailed public case report. Not announcing routes on 2026-09-15 despite current ASN-DROP inclusion. Treat as a tombstone until route and holder are revalidated. Current RIPEstat enrichment reports no announcement.; Previously tracked historical infrastructure; not currently enforced.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS214209","ASN Number":"214209","Network Name":"INTERNET-MAGNATE Internet Magnate (Pty) Ltd","Aliases":"Internet Magnate (Pty) Ltd","Provider Family":"magnates.co.za","RIR Country Code":"ZA","Country Name":"South Africa","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.48","ipapi Rank":"897","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #897 with 13.48% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"17","IPsum IPs":"14","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"11","Talos 2024 IPs":"0","Multi-list IPs":"9","Listed-IP Country Mix":"ZA:14, RO:3"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS214210","ASN Number":"214210","Network Name":"ELEMENT PE Pigin Alexander Lirovich","Aliases":"PE Pigin Alexander Lirovich","Provider Family":"","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #964 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS214218","ASN Number":"214218","Network Name":"MIRONOV PE Mironova Lyudmila Alexandrovna","Aliases":"PE Mironova Lyudmila Alexandrovna","Provider Family":"","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"35.55","ipapi Rank":"554","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #554 with 35.55% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS214268","ASN Number":"214268","Network Name":"ORANGE ORANGE LLC","Aliases":"ORANGE LLC","Provider Family":"leveltele.com","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.32","ipapi Rank":"759","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #759 with 17.32% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS214309","ASN Number":"214309","Network Name":"AURORIX Aurorix Gaming Solutions Limited","Aliases":"Aurorix Gaming Solutions Limited","Provider Family":"aurorix.net","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.89","ipapi Rank":"930","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #930 with 12.89% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"4","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"DE:4"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS214365","ASN Number":"214365","Network Name":"HypefoxNet Hypefox AB","Aliases":"Hypefox AB","Provider Family":"hypefox.net","RIR Country Code":"SE","Country Name":"Sweden","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"25.39","ipapi Rank":"619","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #619 with 25.39% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS214481","ASN Number":"214481","Network Name":"wczapkowicz-as Wojciech Czapkowicz","Aliases":"Wojciech Czapkowicz","Provider Family":"chunkserve.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #998 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"14","IPsum IPs":"7","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"3","Data-Shield IPs":"4","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"NL:9, PL:5"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS214803","ASN Number":"214803","Network Name":"BRNCHOST Baran Cirak","Aliases":"Baran Cirak","Provider Family":"brnchost.com","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"26.95","ipapi Rank":"605","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #605 with 26.95% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS214961","ASN Number":"214961","Network Name":"STELLARGROUPSAS Stellar Group SAS","Aliases":"Stellar Group SAS","Provider Family":"abuse-manager.com","RIR Country Code":"FR","Country Name":"France","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"22.46","ipapi Rank":"659","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #659 with 22.46% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"54","IPsum IPs":"54","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"3","Listed-IP Country Mix":"FR:54"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS215115","ASN Number":"215115","Network Name":"Optics-Kuban-AS Kovalishin Alexey Sergeevich PE","Aliases":"Kovalishin Alexey Sergeevich PE","Provider Family":"","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.65","ipapi Rank":"841","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #841 with 14.65% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS215125","ASN Number":"215125","Network Name":"Cyberology-AS Church of Cyberology","Aliases":"Church of Cyberology","Provider Family":"cyberology.nl","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"187","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #187 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"174","IPsum IPs":"154","IPsum Score >=3":"63","IPsum Score >=5":"18","Open-Proxy IPs":"0","Data-Shield IPs":"68","Talos 2024 IPs":"23","Multi-list IPs":"68","Listed-IP Country Mix":"NL:174"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS215208","ASN Number":"215208","Network Name":"PT-Citra-Celebas-Multimedia PT Citra Celebas Multimedia","Aliases":"PrimaHome; historical: Dolphin 1337 Limited; historical: DOLPHINNETWORKS","Provider Family":"","RIR Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Eyeball ISP with limited originated/leased prefixes","Category":"Legacy hosting/VPS watchlist","Evidence Level":"Weak","FP Risk":"High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2025-05-01","Source IDs":"S05, X004, X005, N01","Evidence Summary":"Excedo's 2025 BPH analysis concerned the former holder Dolphin 1337 Limited. The current RIPE object was created on 2026-04-20 for Indonesian ISP PT Citra Celebas Multimedia, and bgp.tools classifies it as an active eyeball network. The historical reputation must not be transferred to the new holder.","Analyst Notes":"The dirty-list rationale belongs to a former operator. Country or impossible-travel policy may still apply, but ASN reputation should be reset.","Current Community Feed Count":"1","Current Listed IPs":"4","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"4","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"ID:4"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS215253","ASN Number":"215253","Network Name":"FAMKO-MOJEMEDIA-AS FAMKO Paulina Zwiazek","Aliases":"FAMKO Paulina Zwiazek","Provider Family":"mojemedia.net.pl","RIR Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.89","ipapi Rank":"937","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #937 with 12.89% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS215288","ASN Number":"215288","Network Name":"HOBI-ONE Michele Branchini","Aliases":"Michele Branchini","Provider Family":"as215288.net","RIR Country Code":"IT","Country Name":"Italy","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.63","ipapi Rank":"806","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #806 with 15.63% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"20","IPsum IPs":"20","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"IT:20"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS215416","ASN Number":"215416","Network Name":"MagNet VIGEN PETROSYAN trading as \"SAMVELI\"","Aliases":"VIGEN PETROSYAN trading as SAMVELI","Provider Family":"","RIR Country Code":"AM","Country Name":"Armenia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"27.34","ipapi Rank":"599","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #599 with 27.34% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS215439","ASN Number":"215439","Network Name":"PLAY2GO-NET PLAY2GO INTERNATIONAL LIMITED","Aliases":"","Provider Family":"PLAY2GO INTERNATIONAL LIMITED","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Conditional fast-flux ASN seed","Evidence Level":"Context","FP Risk":"High","Recommended Use":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Conditional analytic","Actor / Campaign":"Fast-flux phishing infrastructure","Last Evidence":"2026-09-29","Source IDs":"N38, N01","Evidence Summary":"Conditional fast-flux analytic includes this ASN. This supports source-scoped review, not provider-wide malicious attribution.","Analyst Notes":"Do not enable from this source alone.","Current Community Feed Count":"3","Current Listed IPs":"133","IPsum IPs":"65","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"40","Data-Shield IPs":"44","Talos 2024 IPs":"0","Multi-list IPs":"16","Listed-IP Country Mix":"DE:76, FI:27, NL:24, SE:6"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS215462","ASN Number":"215462","Network Name":"Reserved ASN, origin withdrawn 2026-10-02 (former BUGGZ-HOSTING Noel Nayasha Materke)","Aliases":"Noel Nayasha Materke; BUGGZ-HOSTING; BUGGZ-HOSTING Noel Nayasha Materke","Provider Family":"sircrosar.net","RIR Country Code":"ZZ","Country Name":"Unknown","Geography Scope":"Unknown","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"reserved","Route Status":"Not currently originating","Route Last Seen":"2026-10-02","Network Type":"Hosting / VPS / proxy","Category":"Former ASN-DROP; registration and routing anomaly","Evidence Level":"Historical / lifecycle","FP Risk":"Very High","Recommended Use":"Disabled by default. Retain history and review current assignment, origin, and exact indicators before any enforcement.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"427","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-07","Source IDs":"S01, S02, N01, S03","Evidence Summary":"Present in the 2026-09-15 ASN-DROP snapshot and absent from the 2026-09-29 snapshot; delisting does not establish benignness. Direct RDAP returns no record, and the origin last observed on 2026-10-02 has since been withdrawn.","Analyst Notes":"Routing re-verified 2026-10-07: no current origin, last seen 2026-10-02. Reserved status, absent RDAP object and absent origin together meet the removal test, but the origin has been gone for five days only, so the row is held for lifecycle review rather than removed.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS215654","ASN Number":"215654","Network Name":"GenicheskOnline Genichesk Online LLC","Aliases":"Genichesk Online LLC","Provider Family":"","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.67","ipapi Rank":"889","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #889 with 13.67% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS215761","ASN Number":"215761","Network Name":"MFATIHASAN Muhammed Fatih ASAN","Aliases":"Muhammed Fatih ASAN","Provider Family":"hostingturkiye.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"37.24","ipapi Rank":"548","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #548 with 37.24% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"TR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS215778","ASN Number":"215778","Network Name":"ALPHASTRIKE-HK Alpha Strike Labs GmbH","Aliases":"Alpha Strike Labs GmbH","Provider Family":"alphastrike.io","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"57.71","ipapi Rank":"494","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #494 with 57.71% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"519","IPsum IPs":"494","IPsum Score >=3":"1","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"255","Talos 2024 IPs":"0","Multi-list IPs":"230","Listed-IP Country Mix":"HK:519"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS215813","ASN Number":"215813","Network Name":"SAS-ALTISCORE Association Athena-Heberg","Aliases":"Association Athena-Heberg","Provider Family":"athena-heberg.fr","RIR Country Code":"FR","Country Name":"France","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.58","ipapi Rank":"751","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #751 with 17.58% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS215851","ASN Number":"215851","Network Name":"JOINNET-AS JoinNet LLC","Aliases":"JoinNet LLC","Provider Family":"joinnet.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.11","ipapi Rank":"978","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #978 with 12.11% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS215910","ASN Number":"215910","Network Name":"EDMA-NET Edma Net SHPK","Aliases":"Edma Net SHPK","Provider Family":"","RIR Country Code":"AL","Country Name":"Albania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"25.39","ipapi Rank":"617","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #617 with 25.39% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"AL:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS216020","ASN Number":"216020","Network Name":"JORDANCAPPELLE-AS Jordan Cappelle t/a OCTOHEBERG","Aliases":"Jordan Cappelle t/a OCTOHEBERG","Provider Family":"octoheberg.fr","RIR Country Code":"FR","Country Name":"France","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.92","ipapi Rank":"693","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #693 with 19.92% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS216046","ASN Number":"216046","Network Name":"tele-co-tirana Tele.Co.Albania SHPK","Aliases":"Tele.Co.Albania SHPK","Provider Family":"","RIR Country Code":"AL","Country Name":"Albania","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.06","ipapi Rank":"865","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #865 with 14.06% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS216185","ASN Number":"216185","Network Name":"Biletik_Onlain Biletik-Onlain LTD","Aliases":"Biletik-Onlain LTD","Provider Family":"yapk-service.ru","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.45","ipapi Rank":"848","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #848 with 14.45% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"RU:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS216192","ASN Number":"216192","Network Name":"HIPERONLINE hiperonline iletisim hizmetleri san. tic. ltd. sti.","Aliases":"hiperonline iletisim hizmetleri san. tic","Provider Family":"hiperonline.com.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.38","ipapi Rank":"755","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #755 with 17.38% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS216472","ASN Number":"216472","Network Name":"HS-SYR High Speed For Internet Services L.L.C","Aliases":"High Speed For Internet Services L.L.C","Provider Family":"highspeed-sy.com","RIR Country Code":"SY","Country Name":"Syria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"21.53","ipapi Rank":"668","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #668 with 21.53% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"141","IPsum IPs":"10","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"121","Data-Shield IPs":"14","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"TR:91, SY:36, FR:11, US:3"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS218831","ASN Number":"218831","Network Name":"NL-NET Noah Lingsminat","Aliases":"Noah Lingsminat","Provider Family":"nl-net.de","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.97","ipapi Rank":"740","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #740 with 17.97% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"AT:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS218850","ASN Number":"218850","Network Name":"SETURA-YAZILIM SETURA YAZILIM VE TICARET LIMITED SIRKETI","Aliases":"SETURA YAZILIM VE TICARET LIMITED SIRKET","Provider Family":"setura.tr","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"99.61","ipapi Rank":"460","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #460 with 99.61% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS218923","ASN Number":"218923","Network Name":"SERVIS-NODE-AS SERVIS NODE LLC","Aliases":"SERVIS NODE LLC","Provider Family":"","RIR Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"58.59","ipapi Rank":"493","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #493 with 58.59% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS218984","ASN Number":"218984","Network Name":"AR-Solution REENA DEVI ANURAG SACHAN trading as AR SOLUTION","Aliases":"REENA DEVI ANURAG SACHAN trading as AR S","Provider Family":"serververs.com","RIR Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"21.09","ipapi Rank":"674","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #674 with 21.09% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS219064","ASN Number":"219064","Network Name":"Akenai-Products-AS Akenai Products LTD","Aliases":"Akenai Products LTD","Provider Family":"akenai.team","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #905 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS219181","ASN Number":"219181","Network Name":"POSIINDUSTRIAL PO SI INDUSTRIAL CO., LIMITED","Aliases":"PO SI INDUSTRIAL CO., LIMITED","Provider Family":"ipv4superhub.com","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the Very High band at rank #584 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS219231","ASN Number":"219231","Network Name":"Oretra ORETRA INTERNET VE BILISIM HIZMETLERI LIMITED SIRKETI","Aliases":"ORETRA INTERNET VE BILISIM HIZMETLE","Provider Family":"","RIR Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"95.31","ipapi Rank":"468","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #468 with 95.31% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS219335","ASN Number":"219335","Network Name":"COREVANCE-AS COREVANCE LTD","Aliases":"COREVANCE LTD","Provider Family":"corevance.org","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"11.91","ipapi Rank":"990","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #990 with 11.91% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS219543","ASN Number":"219543","Network Name":"PA1792-AS German Kiselev","Aliases":"German Kiselev","Provider Family":"","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #745 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"10","IPsum IPs":"7","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"7","Talos 2024 IPs":"0","Multi-list IPs":"4","Listed-IP Country Mix":"PL:10"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS262880","ASN Number":"262880","Network Name":"AS262880 - RADAR WISP LTDA","Aliases":"RADAR WISP LTDA","Provider Family":"radarinternet.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.17","ipapi Rank":"704","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #704 with 19.17% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS262909","ASN Number":"262909","Network Name":"AS262909 - JK TELECOMUNICACOES LTDA","Aliases":"JK TELECOMUNICACOES LTDA","Provider Family":"jknet.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"reserved","Route Status":"Not currently originating","Route Last Seen":"2026-10-09","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"50","ipapi Rank":"517","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-09","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #517 with 50% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users. Routing re-verified 2026-10-09: no announced prefixes on two passes, last seen 2026-10-09. Held for lifecycle review; not removed on a days-old absence. RIR delegation file now lists the ASN as reserved and RDAP returns no object (2026-10-09).","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS262988","ASN Number":"262988","Network Name":"AS262988 - Pombonet Telecomunicacoes e Informatica","Aliases":"Pombonet Telecomunicações e Informática","Provider Family":"pombonet.net.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"50.84","ipapi Rank":"508","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #508 with 50.84% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS263284","ASN Number":"263284","Network Name":"AS263284 - MAXXIMO INFORMATICA E TELECOMUNICACAO LTDA","Aliases":"MAXXIMO INFORMATICA E TELECOMUNICACAO LT","Provider Family":"meganet.net.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"99.8","ipapi Rank":"457","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #457 with 99.8% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS263351","ASN Number":"263351","Network Name":"AS263351 - Micron Servicos de Tecnologia Ltda","Aliases":"Micron Servicos de Tecnologia Ltda","Provider Family":"micron.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"34.18","ipapi Rank":"559","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #559 with 34.18% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS263536","ASN Number":"263536","Network Name":"AS263536 - MICROSET MAQUINAS E SERVICOS LTDA","Aliases":"MICROSET MAQUINAS E SERVICOS LTDA","Provider Family":"microset.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"44.64","ipapi Rank":"530","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #530 with 44.64% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS263641","ASN Number":"263641","Network Name":"AS263641 - TCF Telecomunicacoes Campo Florido Ltda","Aliases":"TCF Telecomunicações Campo Florido Ltda","Provider Family":"tcftelecom.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"31.49","ipapi Rank":"577","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #577 with 31.49% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS263947","ASN Number":"263947","Network Name":"AS263947 - VirtualSpace Telecom","Aliases":"VirtualSpace Telecom","Provider Family":"virtualspaceprovedor.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"23.36","ipapi Rank":"647","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #647 with 23.36% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS263949","ASN Number":"263949","Network Name":"AS263949 - Mega Internet LTDA ME","Aliases":"Mega Internet LTDA ME","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.45","ipapi Rank":"854","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #854 with 14.45% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS263983","ASN Number":"263983","Network Name":"AS263983 - CIT INFORMATICA","Aliases":"CIT INFORMATICA","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.85","ipapi Rank":"716","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #716 with 18.85% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS264009","ASN Number":"264009","Network Name":"AS264009 - INFIX TELECOM LTDA","Aliases":"INFIX TELECOM LTDA","Provider Family":"tbonet.net.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.75","ipapi Rank":"774","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #774 with 16.75% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS264014","ASN Number":"264014","Network Name":"AS264014 - Led Internet Eireli","Aliases":"Led Internet Eireli","Provider Family":"ledinternet.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"169","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #169 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS264051","ASN Number":"264051","Network Name":"AS264051 - PLAYMAIS FIBRA SCM LTDA","Aliases":"PLAYMAIS FIBRA SCM LTDA","Provider Family":"playmaisfibra.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"46.97","ipapi Rank":"527","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #527 with 46.97% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS264133","ASN Number":"264133","Network Name":"AS264133 - TX WEB TELECOM LTDA","Aliases":"TX WEB TELECOM LTDA","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.97","ipapi Rank":"737","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #737 with 17.97% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS264217","ASN Number":"264217","Network Name":"AS264217 - Sem Fone Telecomunicacoes Ltda","Aliases":"Sem Fone Telecomunicações Ltda","Provider Family":"semfone.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"168","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #168 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS264280","ASN Number":"264280","Network Name":"AS264280 - Eagle Redes de Telecomunicacoes Ltda","Aliases":"Eagle Redes de Telecomunicacoes Ltda","Provider Family":"eagleredes.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"99.9","ipapi Rank":"453","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #453 with 99.9% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS264697","ASN Number":"264697","Network Name":"AS264697 - LEWTEL SRL","Aliases":"LEWTEL SRL","Provider Family":"lewtel.com.ar","RIR Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.54","ipapi Rank":"894","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #894 with 13.54% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS265131","ASN Number":"265131","Network Name":"AS265131 - GP4 SERVICOS E TECNOLOGIA LTDA","Aliases":"GP4 SERVICOS E TECNOLOGIA LTDA","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"66.67","ipapi Rank":"481","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #481 with 66.67% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS265191","ASN Number":"265191","Network Name":"AS265191 - Sapucaia Comercio e informatica ltda - me","Aliases":"Sapucaia Comercio e informatica ltd","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.76","ipapi Rank":"800","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #800 with 15.76% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS265201","ASN Number":"265201","Network Name":"AS265201 - MEGANET SERVICOS DE COMUNICACAO E MULTIMIDIA LTDA","Aliases":"MEGANET SERVICOS DE COMUNICACAO E MULTIM","Provider Family":"telecab.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"11.82","ipapi Rank":"1000","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #1000 with 11.82% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS265260","ASN Number":"265260","Network Name":"AS265260 - JOSE APARECIDO PEREIRA DA SILVA TELNET - ME","Aliases":"JOSE APARECIDO PEREIRA DA SILVA TEL","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.41","ipapi Rank":"789","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #789 with 16.41% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"5","IPsum IPs":"5","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:5"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS265282","ASN Number":"265282","Network Name":"AS265282 - DOMINA NET TELECOM","Aliases":"DOMINA NET TELECOM","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"176","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #176 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS265410","ASN Number":"265410","Network Name":"Reserved ASN, origin withdrawn 2026-09-30 (former AS265410 - JL INFORMATICA E TELECOM LTDA - ME)","Aliases":"JL INFORMATICA E TELECOM LTDA - ME; AS265410 - JL INFORMATICA E TELECOM LTDA - ME","Provider Family":"","RIR Country Code":"ZZ","Country Name":"Unknown","Geography Scope":"Unknown","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"reserved","Route Status":"Not currently originating","Route Last Seen":"2026-09-30","Network Type":"Isp","Category":"Registration and routing anomaly","Evidence Level":"Historical / lifecycle","FP Risk":"Very High","Recommended Use":"Disabled by default. Retain history and review current assignment, origin, and exact indicators before any enforcement.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"44.44","ipapi Rank":"531","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-02","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #531 with 44.44% observed abuse concentration (Very High) on 2026-09-29. Current delegated RIR data marks the ASN reserved with no current holder or country, direct RDAP returns no record, and the origin last observed on 2026-09-30 has since been withdrawn. The former holder and country remain only as historical context.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users. Current RIR and routing state require lifecycle review. Routing re-verified 2026-10-02: no current origin, last seen 2026-09-30. Authoritative RDAP returns no object for this number. Reserved status, absent RDAP object and absent origin together meet the removal test, but the origin has been gone for two days only, so the row is held for lifecycle review rather than removed on a 48 hour absence.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS265464","ASN Number":"265464","Network Name":"AS265464 - ESTACAONET TELECOM","Aliases":"ESTACAONET TELECOM","Provider Family":"estacaonet.net.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"33.33","ipapi Rank":"566","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #566 with 33.33% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS265574","ASN Number":"265574","Network Name":"AS265574 - IPTVTEL COMUNICACIONES S DE RL DE CV","Aliases":"IPTVTEL COMUNICACIONES S DE RL DE C","Provider Family":"","RIR Country Code":"MX","Country Name":"Mexico","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"25.68","ipapi Rank":"614","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #614 with 25.68% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"3","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"3","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"MX:3"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS265579","ASN Number":"265579","Network Name":"AS265579 - TELECOMUNICACIONES OTOMIES","Aliases":"TELECOMUNICACIONES OTOMIES","Provider Family":"","RIR Country Code":"MX","Country Name":"Mexico","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"51.76","ipapi Rank":"506","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #506 with 51.76% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"23","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"23","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"MX:23"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS265772","ASN Number":"265772","Network Name":"AS265772 - SOTO DANIEL MARIO (Internet Compus)","Aliases":"SOTO DANIEL MARIO (Internet Compus)","Provider Family":"compusinformatica.com.ar","RIR Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.73","ipapi Rank":"697","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #697 with 19.73% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS265868","ASN Number":"265868","Network Name":"AS265868 - GETCOM SAS","Aliases":"GETCOM SAS","Provider Family":"","RIR Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.75","ipapi Rank":"721","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #721 with 18.75% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS265879","ASN Number":"265879","Network Name":"AS265879 - COOPERATIVA DE OBRAS Y SERVICIOS PUBLICOS DE CANALS LIMITADA","Aliases":"COOPERATIVA DE OBRAS Y SERVICIOS PUBLICO","Provider Family":"canalsnet.com.ar","RIR Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"55.86","ipapi Rank":"497","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #497 with 55.86% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"AR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS265914","ASN Number":"265914","Network Name":"AS265914 - TRIUNFO FIBRA","Aliases":"TRIUNFO FIBRA","Provider Family":"triunfointernet.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.55","ipapi Rank":"844","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #844 with 14.55% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS266270","ASN Number":"266270","Network Name":"AS266270 - WBR Telecom","Aliases":"WBR Telecom","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"25.59","ipapi Rank":"615","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #615 with 25.59% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS266498","ASN Number":"266498","Network Name":"AS266498 - UNIVERSO FIBER COMUNICACAO MULTIMIDIA","Aliases":"UNIVERSO FIBER COMUNICACAO MULTIMIDIA","Provider Family":"universofiber.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"99.8","ipapi Rank":"456","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #456 with 99.8% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS266583","ASN Number":"266583","Network Name":"AS266583 - TELXE DO BRASIL TELECOMUNICACOES LTDA","Aliases":"TELXE DO BRASIL TELECOMUNICACOES LTDA","Provider Family":"telxe.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #915 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS266631","ASN Number":"266631","Network Name":"AS266631 - Enoki & Ruiz Ltda - ME","Aliases":"Enoki & Ruiz Ltda - ME","Provider Family":"futuranet.net.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"50","ipapi Rank":"513","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #513 with 50% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS266705","ASN Number":"266705","Network Name":"AS266705 - GABRIEL FRANCISCO ERBETTA Y MARIANO ANDRES CARRIZO RICHELET SOCIEDAD DE HECHO (TELNET SOLUCIONES)","Aliases":"GABRIEL FRANCISCO ERBETTA Y MARIANO ANDR","Provider Family":"jumpnetcorp.com.ar","RIR Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.71","ipapi Rank":"838","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #838 with 14.71% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"11","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"10","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"AR:11"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS266742","ASN Number":"266742","Network Name":"AS266742 - SOLUCIONES DCN NETWORK C.A","Aliases":"SOLUCIONES DCN NETWORK C.A","Provider Family":"","RIR Country Code":"VE","Country Name":"Venezuela","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"27.34","ipapi Rank":"600","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #600 with 27.34% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"14","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"12","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"VE:14"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS266852","ASN Number":"266852","Network Name":"AS266852 - SOCIEDAD PIRQUE NET LIMITADA","Aliases":"SOCIEDAD PIRQUE NET LIMITADA","Provider Family":"intercable.cl","RIR Country Code":"CL","Country Name":"Chile","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.7","ipapi Rank":"801","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #801 with 15.7% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS266953","ASN Number":"266953","Network Name":"AS266953 - ITMINDS CONSULTORIA EM TECNOLOGIA DA INFORMACAO","Aliases":"ITMINDS CONSULTORIA EM TECNOLOGIA D","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"104","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #104 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS267325","ASN Number":"267325","Network Name":"AS267325 - USBINF INFORMATICA LTDA - ME","Aliases":"USBINF INFORMATICA LTDA - ME","Provider Family":"usbinternet.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"66.67","ipapi Rank":"480","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #480 with 66.67% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS267677","ASN Number":"267677","Network Name":"AS267677 - COMERCIALIZADORA E IMPORTADORA PRESTOM CHILE LTDA","Aliases":"COMERCIALIZADORA E IMPORTADORA PRESTOM C","Provider Family":"prestomwill.cl","RIR Country Code":"CL","Country Name":"Chile","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"21.39","ipapi Rank":"671","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #671 with 21.39% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS267690","ASN Number":"267690","Network Name":"AS267690 - ELDA SALERNO(FULLNET)","Aliases":"ELDA SALERNO(FULLNET)","Provider Family":"","RIR Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"41.93","ipapi Rank":"537","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #537 with 41.93% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"5","IPsum IPs":"5","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"AR:5"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS267889","ASN Number":"267889","Network Name":"AS267889 - PROVINSAT CAPITAL SA","Aliases":"PROVINSAT CAPITAL SA","Provider Family":"provinsat.com.ar","RIR Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.75","ipapi Rank":"719","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #719 with 18.75% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"3","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"AR:3"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS267952","ASN Number":"267952","Network Name":"AS267952 - HILINK TECNOLOGIA E COMUNICACAO LTDA","Aliases":"HILINK TECNOLOGIA E COMUNICACAO LTD","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.79","ipapi Rank":"943","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #943 with 12.79% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS268106","ASN Number":"268106","Network Name":"AS268106 - Link Speed","Aliases":"Link Speed","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"98","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #98 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS268502","ASN Number":"268502","Network Name":"AS268502 - Sinal do Ceu Telecom Comercio e Servicos Ltda","Aliases":"Sinal do Ceu Telecom Comercio e Servicos","Provider Family":"sinaldoceu.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"96","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #96 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS268538","ASN Number":"268538","Network Name":"AS268538 - Conecta Network Telecom LTDA","Aliases":"Conecta Network Telecom LTDA","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"97","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #97 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS268757","ASN Number":"268757","Network Name":"AS268757 - BRITO & GONCALVES LTDA ME","Aliases":"BRITO & GONCALVES LTDA ME","Provider Family":"pantanaltelecom.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"33.33","ipapi Rank":"563","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #563 with 33.33% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS268876","ASN Number":"268876","Network Name":"AS268876 - CE TECH INTERNET LTDA","Aliases":"CE TECH INTERNET LTDA","Provider Family":"cetech.net.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #837 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS268983","ASN Number":"268983","Network Name":"AS268983 - NAXOS TELECOM","Aliases":"NAXOS TELECOM","Provider Family":"naxosfibra.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"99.8","ipapi Rank":"455","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #455 with 99.8% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS269160","ASN Number":"269160","Network Name":"AS269160 - Dblock Net","Aliases":"Dblock Net","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.16","ipapi Rank":"825","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #825 with 15.16% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS269182","ASN Number":"269182","Network Name":"AS269182 - PLUGAR TELECOM","Aliases":"PLUGAR TELECOM","Provider Family":"plugartelecom.net.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"60","ipapi Rank":"492","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #492 with 60% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS269195","ASN Number":"269195","Network Name":"AS269195 - J. CALUX & CIA LTDA","Aliases":"J. CALUX & CIA LTDA","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.39","ipapi Rank":"859","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #859 with 14.39% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS269279","ASN Number":"269279","Network Name":"AS269279 - ARENA TELECOM COMERCIO DE EQUIPAMENTOS DE INFORMA","Aliases":"ARENA TELECOM COMERCIO DE EQUIPAMENTOS D","Provider Family":"arenaconnect.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"80.08","ipapi Rank":"474","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #474 with 80.08% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS269357","ASN Number":"269357","Network Name":"AS269357 - DELTA TELECOM","Aliases":"DELTA TELECOM","Provider Family":"delta-telecom.net","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.86","ipapi Rank":"694","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #694 with 19.86% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS269422","ASN Number":"269422","Network Name":"AS269422 - GKG NET TELECON LTDA","Aliases":"GKG NET TELECON LTDA","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"36.36","ipapi Rank":"550","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #550 with 36.36% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS269427","ASN Number":"269427","Network Name":"AS269427 - ONSTARK SISTEMAS INTELIGENTES LTDA -EPP","Aliases":"ONSTARK SISTEMAS INTELIGENTES LTDA -EPP","Provider Family":"onstark.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #1000 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS269494","ASN Number":"269494","Network Name":"AS269494 - GPR NET COMUNICACOES EIRELI","Aliases":"GPR NET COMUNICACOES EIRELI","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.14","ipapi Rank":"827","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #827 with 15.14% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS269546","ASN Number":"269546","Network Name":"AS269546 - BITNET TELECOM","Aliases":"BITNET TELECOM","Provider Family":"bitnetinternet.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"33.33","ipapi Rank":"564","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #564 with 33.33% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS269630","ASN Number":"269630","Network Name":"AS269630 - Jose Carlos Santana Junior-ME","Aliases":"José Carlos Santana Júnior-ME","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.7","ipapi Rank":"948","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #948 with 12.7% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS269663","ASN Number":"269663","Network Name":"AS269663 - CONNECTLINK TECH","Aliases":"CONNECTLINK TECH","Provider Family":"connectlinksp.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"23.73","ipapi Rank":"640","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #640 with 23.73% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS269771","ASN Number":"269771","Network Name":"AS269771 - PRINTER-NET-SERVICE, C.A.","Aliases":"PRINTER-NET-SERVICE, C.A.","Provider Family":"pns.com.ve","RIR Country Code":"VE","Country Name":"Venezuela","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.02","ipapi Rank":"796","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #796 with 16.02% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"35","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"35","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"VE:35"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS269901","ASN Number":"269901","Network Name":"AS269901 - MARAVECA TELECOMUNICACIONES C.A","Aliases":"MARAVECA TELECOMUNICACIONES C.A","Provider Family":"maraveca.com","RIR Country Code":"VE","Country Name":"Venezuela","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.45","ipapi Rank":"852","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #852 with 14.45% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS269930","ASN Number":"269930","Network Name":"AS269930 - CAMPOS FARIAS GUILHERME","Aliases":"CAMPOS FARIAS GUILHERME","Provider Family":"alfa.net.py","RIR Country Code":"PY","Country Name":"Paraguay","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.5","ipapi Rank":"960","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #960 with 12.5% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS270062","ASN Number":"270062","Network Name":"AS270062 - FIBERNET TV SAS","Aliases":"FIBERNET TV SAS","Provider Family":"fibernettv.com.co","RIR Country Code":"CO","Country Name":"Colombia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.72","ipapi Rank":"749","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #749 with 17.72% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"34","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"33","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"CO:34"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS270075","ASN Number":"270075","Network Name":"AS270075 - SUPER REDES S.A.S","Aliases":"SUPER REDES S.A.S","Provider Family":"superredes.co","RIR Country Code":"CO","Country Name":"Colombia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"24.27","ipapi Rank":"632","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #632 with 24.27% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"53","IPsum IPs":"3","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"49","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"2","Listed-IP Country Mix":"CO:53"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS270168","ASN Number":"270168","Network Name":"AS270168 - Alejandro Uballe Montoya","Aliases":"Alejandro Uballe Montoya","Provider Family":"","RIR Country Code":"MX","Country Name":"Mexico","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #966 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS270207","ASN Number":"270207","Network Name":"AS270207 - MULTICARRIER JE S. DE R.L. DE C.V.","Aliases":"MULTICARRIER JE S. DE R.L. DE C.V.","Provider Family":"multicarrier.com.mx","RIR Country Code":"MX","Country Name":"Mexico","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.82","ipapi Rank":"940","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #940 with 12.82% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"34","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"33","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"MX:34"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS270226","ASN Number":"270226","Network Name":"AS270226 - UGI INTERNET & TV S.A. de C.V.","Aliases":"UGI INTERNET & TV S.A. de C.V.","Provider Family":"ugi.mx","RIR Country Code":"MX","Country Name":"Mexico","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.36","ipapi Rank":"727","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #727 with 18.36% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS270268","ASN Number":"270268","Network Name":"AS270268 - FiberPon telecom","Aliases":"FiberPon telecom","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"55.76","ipapi Rank":"498","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #498 with 55.76% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"3","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"2","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"BR:3"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS270320","ASN Number":"270320","Network Name":"AS270320 - X NET","Aliases":"X NET","Provider Family":"xnetfibra.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.13","ipapi Rank":"732","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #732 with 18.13% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS270368","ASN Number":"270368","Network Name":"AS270368 - T. R. TELECOMUNICACOES LTDA","Aliases":"T. R. TELECOMUNICACOES LTDA","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"28.03","ipapi Rank":"596","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #596 with 28.03% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"26","IPsum IPs":"26","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:26"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS270433","ASN Number":"270433","Network Name":"AS270433 - maicon narciso me","Aliases":"maicon narciso me","Provider Family":"midiatelecom.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"57.14","ipapi Rank":"495","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #495 with 57.14% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS270581","ASN Number":"270581","Network Name":"AS270581 - JET NETWORK TELECOMUNICACAO LTDA","Aliases":"JET NETWORK TELECOMUNICAÇÃO LTDA","Provider Family":"jetnetwork.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"49.8","ipapi Rank":"519","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #519 with 49.8% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS270837","ASN Number":"270837","Network Name":"AS270837 - Imartech Fibra","Aliases":"Imartech Fibra","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"50","ipapi Rank":"518","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #518 with 50% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS270923","ASN Number":"270923","Network Name":"AS270923 - FENIX BRASIL","Aliases":"FENIX BRASIL","Provider Family":"fnxtelecom.net.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"33.33","ipapi Rank":"568","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #568 with 33.33% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS270955","ASN Number":"270955","Network Name":"AS270955 - LINK DIGITAL SOLUCOES EM INTERNET LTDA","Aliases":"LINK DIGITAL SOLUCOES EM INTERNET L","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.06","ipapi Rank":"870","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #870 with 14.06% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS271380","ASN Number":"271380","Network Name":"AS271380 - GLOBAL CONECTA TELECOM EIRELI","Aliases":"GLOBAL CONECTA TELECOM EIRELI","Provider Family":"globalconecta.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"179","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #179 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS271388","ASN Number":"271388","Network Name":"AS271388 - WEB Provedor","Aliases":"WEB Provedor","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"197","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #197 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS271410","ASN Number":"271410","Network Name":"AS271410 - Smart Servico de Internet Ltda","Aliases":"Smart Serviço de Internet Ltda","Provider Family":"provedorsmartsp.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"33.33","ipapi Rank":"565","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #565 with 33.33% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS271412","ASN Number":"271412","Network Name":"AS271412 - FR Sousa Telecomunicacoes LTDA - ME","Aliases":"FR Sousa Telecomunicações LTDA - ME","Provider Family":"multpontosfranca.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"39.92","ipapi Rank":"539","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #539 with 39.92% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS271562","ASN Number":"271562","Network Name":"AS271562 - WT NET COMUNICACAO LTDA","Aliases":"WT NET COMUNICACAO LTDA","Provider Family":"winetfsa.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"30.86","ipapi Rank":"582","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #582 with 30.86% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"2","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS271843","ASN Number":"271843","Network Name":"AS271843 - LARA INGENIERIA EN TECNOLOGIA Y TELECOMUNICACIONES LIMITADA (SOLUCIONES INTERLAN)","Aliases":"LARA INGENIERIA EN TECNOLOGIA Y TELECOMU","Provider Family":"interlan.cl","RIR Country Code":"CL","Country Name":"Chile","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.84","ipapi Rank":"744","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #744 with 17.84% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"4","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"4","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"CL:4"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS272042","ASN Number":"272042","Network Name":"AS272042 - Garay Diego Sebastian","Aliases":"Garay Diego Sebastian","Provider Family":"infomain.com.ar","RIR Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.46","ipapi Rank":"724","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #724 with 18.46% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS272073","ASN Number":"272073","Network Name":"AS272073 - SILKGLOBAL DOMINICANA SRL","Aliases":"SILKGLOBAL DOMINICANA SRL","Provider Family":"silkglobal.com","RIR Country Code":"DO","Country Name":"Dominican Republic","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.21","ipapi Rank":"792","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #792 with 16.21% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS272090","ASN Number":"272090","Network Name":"AS272090 - ALDERETE RIVAS JORDAN TOMAS SEBASTIAN (COMUNICATE INTERNET)","Aliases":"ALDERETE RIVAS JORDAN TOMAS SEBASTIAN (C","Provider Family":"netplay.com.ar","RIR Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"21.88","ipapi Rank":"662","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #662 with 21.88% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"9","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"9","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"AR:9"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS272102","ASN Number":"272102","Network Name":"AS272102 - BESSER SOLUTIONS C.A.","Aliases":"BESSER SOLUTIONS C.A.","Provider Family":"bessersolutions.com","RIR Country Code":"VE","Country Name":"Venezuela","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"23.93","ipapi Rank":"635","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #635 with 23.93% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS272149","ASN Number":"272149","Network Name":"AS272149 - DLD SERVICIO SRL","Aliases":"DLD SERVICIO SRL","Provider Family":"dldservicio.com","RIR Country Code":"DO","Country Name":"Dominican Republic","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"50.39","ipapi Rank":"511","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #511 with 50.39% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"10","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"10","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"DO:10"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS272405","ASN Number":"272405","Network Name":"AS272405 - Jair Lozano","Aliases":"Jair Lozano","Provider Family":"","RIR Country Code":"MX","Country Name":"Mexico","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.99","ipapi Rank":"922","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #922 with 12.99% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"24","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"24","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"MX:24"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS272575","ASN Number":"272575","Network Name":"AS272575 - DELTA R SEGURANCA E SERVICOS","Aliases":"DELTA R SEGURANCA E SERVICOS","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #978 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS272605","ASN Number":"272605","Network Name":"AS272605 - GRUPO ULTRA FIBRA","Aliases":"GRUPO ULTRA FIBRA","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.15","ipapi Rank":"915","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #915 with 13.15% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS272741","ASN Number":"272741","Network Name":"AS272741 - ATLANTICA TELECOMUNICACOES LTDA","Aliases":"ATLANTICA TELECOMUNICAÇÕES LTDA","Provider Family":"atlanticatelecom.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.97","ipapi Rank":"831","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #831 with 14.97% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS272791","ASN Number":"272791","Network Name":"AS272791 - Riann Martins de Oliveira - ME","Aliases":"Riann Martins de Oliveira - ME","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.06","ipapi Rank":"863","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #863 with 14.06% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS272876","ASN Number":"272876","Network Name":"AS272876 - EDWIN RAYMUNDO HERNANDEZ PEC (IMPORTADORA Y EXPORTADORA INTERCEL)","Aliases":"EDWIN RAYMUNDO HERNÁNDEZ PEC (IMPOR","Provider Family":"","RIR Country Code":"GT","Country Name":"Guatemala","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"180","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #180 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"4","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"4","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"GT:4"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS272954","ASN Number":"272954","Network Name":"AS272954 - VUELATECHNOLOGY S.A.S.","Aliases":"VUELATECHNOLOGY S.A.S.","Provider Family":"","RIR Country Code":"EC","Country Name":"Ecuador","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"50.59","ipapi Rank":"510","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #510 with 50.59% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"7","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"6","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"EC:7"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS272990","ASN Number":"272990","Network Name":"AS272990 - AYSATEC TELECOMUNICACIONES S.A.S.","Aliases":"AYSATEC TELECOMUNICACIONES S.A.S.","Provider Family":"aysatecsas.com.co","RIR Country Code":"CO","Country Name":"Colombia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"24.61","ipapi Rank":"627","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #627 with 24.61% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"CO:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273034","ASN Number":"273034","Network Name":"AS273034 - COMPANIA DE TELECOMUNICACIONES LEON & RODAS LR-COMPTEL S.A.","Aliases":"COMPAÑIA DE TELECOMUNICACIONES LEON & RO","Provider Family":"workcom.ec","RIR Country Code":"EC","Country Name":"Ecuador","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.75","ipapi Rank":"720","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #720 with 18.75% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273061","ASN Number":"273061","Network Name":"AS273061 - VOZ Y TELEVISION SOCIEDAD ANONIMA CERRADA","Aliases":"VOZ Y TELEVISION SOCIEDAD ANONIMA CERRAD","Provider Family":"vozytelevision.org","RIR Country Code":"PE","Country Name":"Peru","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.41","ipapi Rank":"783","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #783 with 16.41% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273113","ASN Number":"273113","Network Name":"AS273113 - ONERED JWG532 SRL","Aliases":"ONERED JWG532 SRL","Provider Family":"","RIR Country Code":"DO","Country Name":"Dominican Republic","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"49.22","ipapi Rank":"520","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #520 with 49.22% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"45","IPsum IPs":"45","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"DO:45"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273123","ASN Number":"273123","Network Name":"AS273123 - CRAMCOMNET CIA.LTDA.","Aliases":"CRAMCOMNET CIA.LTDA.","Provider Family":"flylifecuador.com","RIR Country Code":"EC","Country Name":"Ecuador","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.7","ipapi Rank":"950","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #950 with 12.7% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273134","ASN Number":"273134","Network Name":"AS273134 - HOLA TELECOMUNICACINES COLOMBIA S.A.S","Aliases":"HOLA TELECOMUNICACINES COLOMBIA S.A.S","Provider Family":"holainternet.com.co","RIR Country Code":"CO","Country Name":"Colombia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.72","ipapi Rank":"945","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #945 with 12.72% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"25","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"22","Data-Shield IPs":"3","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"CO:25"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273142","ASN Number":"273142","Network Name":"AS273142 - SERVICIOS DE TELCOMUNICACIONES LATEVECOM CIA LTDA","Aliases":"SERVICIOS DE TELCOMUNICACIONES LATEVECOM","Provider Family":"fiberpon.net","RIR Country Code":"EC","Country Name":"Ecuador","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"30.47","ipapi Rank":"584","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #584 with 30.47% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273187","ASN Number":"273187","Network Name":"AS273187 - FIESTA TELECOMUNICACIONES SAS","Aliases":"FIESTA TELECOMUNICACIONES SAS","Provider Family":"ftc.net.co","RIR Country Code":"CO","Country Name":"Colombia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.41","ipapi Rank":"784","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #784 with 16.41% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273195","ASN Number":"273195","Network Name":"AS273195 - INTERPLUSNET EC CIA. LTDA.","Aliases":"INTERPLUSNET EC CIA. LTDA.","Provider Family":"interplus.net.ec","RIR Country Code":"EC","Country Name":"Ecuador","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"20.31","ipapi Rank":"687","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #687 with 20.31% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273250","ASN Number":"273250","Network Name":"AS273250 - SOLUCIONES DE TECNOLOGIA JAH SA DE CV","Aliases":"SOLUCIONES DE TECNOLOGIA JAH SA DE CV","Provider Family":"jahwifi.mx","RIR Country Code":"MX","Country Name":"Mexico","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"11.83","ipapi Rank":"998","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #998 with 11.83% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"6","IPsum IPs":"2","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"4","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"MX:6"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273262","ASN Number":"273262","Network Name":"AS273262 - OSWALDO ERIVAN VALTIERRA ORNELAS","Aliases":"OSWALDO ERIVAN VALTIERRA ORNELAS","Provider Family":"","RIR Country Code":"MX","Country Name":"Mexico","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.06","ipapi Rank":"862","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #862 with 14.06% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273306","ASN Number":"273306","Network Name":"AS273306 - CABLE DIVERSION ELIGAMA","Aliases":"CABLE DIVERSION ELIGAMA","Provider Family":"","RIR Country Code":"MX","Country Name":"Mexico","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.96","ipapi Rank":"875","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #875 with 13.96% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273339","ASN Number":"273339","Network Name":"AS273339 - Su@net Provedor Ltda","Aliases":"Su@net Provedor Ltda","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.45","ipapi Rank":"850","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #850 with 14.45% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273433","ASN Number":"273433","Network Name":"AS273433 - INOVAR TELECOM","Aliases":"INOVAR TELECOM","Provider Family":"inovartelecomse.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the Very High band at rank #678 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273470","ASN Number":"273470","Network Name":"AS273470 - WORK TELECOM INTERNET LTDA","Aliases":"WORK TELECOM INTERNET LTDA","Provider Family":"worktelecombj.com.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"99","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #99 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273692","ASN Number":"273692","Network Name":"AS273692 - ULTRA INTERNET LTDA","Aliases":"ULTRA INTERNET LTDA","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.23","ipapi Rank":"815","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #815 with 15.23% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273709","ASN Number":"273709","Network Name":"AS273709 - MR Serv Internet e TV por Assinatura","Aliases":"MR Serv Internet e TV por Assinatur","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"23.83","ipapi Rank":"637","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #637 with 23.83% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273909","ASN Number":"273909","Network Name":"AS273909 - GENIOS SOLUCIONES SRL","Aliases":"GENIOS SOLUCIONES SRL","Provider Family":"geniosoluciones.pro","RIR Country Code":"DO","Country Name":"Dominican Republic","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.36","ipapi Rank":"726","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #726 with 18.36% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273916","ASN Number":"273916","Network Name":"AS273916 - JUAN CARLOS FRANCO LOBO (INTERCOM HN)","Aliases":"JUAN CARLOS FRANCO LOBO (INTERCOM HN)","Provider Family":"intercomhn.com","RIR Country Code":"HN","Country Name":"Honduras","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #965 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS273922","ASN Number":"273922","Network Name":"AS273922 - CONNET S.R.L.","Aliases":"CONNET S.R.L.","Provider Family":"connetsrl.com.ar","RIR Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.14","ipapi Rank":"705","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #705 with 19.14% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274095","ASN Number":"274095","Network Name":"AS274095 - YNS PARTNERS EIRL","Aliases":"YNS PARTNERS EIRL","Provider Family":"ynspartners.com","RIR Country Code":"DO","Country Name":"Dominican Republic","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.67","ipapi Rank":"892","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #892 with 13.67% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274104","ASN Number":"274104","Network Name":"AS274104 - KING WIFI K NETWORK EIRL","Aliases":"KING WIFI K NETWORK EIRL","Provider Family":"kingwifiknetwork.com","RIR Country Code":"DO","Country Name":"Dominican Republic","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the Very High band at rank #653 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274118","ASN Number":"274118","Network Name":"AS274118 - T AND T NETWORKS SOLUTIONS, C.A.","Aliases":"T AND T NETWORKS SOLUTIONS, C.A.","Provider Family":"","RIR Country Code":"VE","Country Name":"Venezuela","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"20.31","ipapi Rank":"686","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #686 with 20.31% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274129","ASN Number":"274129","Network Name":"AS274129 - ABITAVERAS WIRELESS, S.R.L.","Aliases":"ABITAVERAS WIRELESS, S.R.L.","Provider Family":"abitaveraswireless.com","RIR Country Code":"DO","Country Name":"Dominican Republic","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"18.75","ipapi Rank":"723","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #723 with 18.75% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"DO:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274152","ASN Number":"274152","Network Name":"AS274152 - SURFLINK SAS","Aliases":"SURFLINK SAS","Provider Family":"","RIR Country Code":"CO","Country Name":"Colombia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.28","ipapi Rank":"904","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #904 with 13.28% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274155","ASN Number":"274155","Network Name":"AS274155 - DIGITAL DOT GROUP SAS","Aliases":"DIGITAL DOT GROUP SAS","Provider Family":"","RIR Country Code":"CO","Country Name":"Colombia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.67","ipapi Rank":"893","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #893 with 13.67% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274178","ASN Number":"274178","Network Name":"AS274178 - CORPORACION PV NETWORKS S.A.C.","Aliases":"CORPORACIÓN PV NETWORKS S.A.C.","Provider Family":"ten.pe","RIR Country Code":"PE","Country Name":"Peru","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.89","ipapi Rank":"928","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #928 with 12.89% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274191","ASN Number":"274191","Network Name":"AS274191 - CUSATO VICENTE EZEQUIEL (TELERED VGG)","Aliases":"CUSATO VICENTE EZEQUIEL (TELERED VG","Provider Family":"","RIR Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.8","ipapi Rank":"773","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #773 with 16.8% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274202","ASN Number":"274202","Network Name":"AS274202 - GRUPO MULTIMEDIA S&G, C.A","Aliases":"GRUPO MULTIMEDIA S&G, C.A","Provider Family":"conet.com.ve","RIR Country Code":"VE","Country Name":"Venezuela","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #700 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274206","ASN Number":"274206","Network Name":"AS274206 - NORTE VISION CA","Aliases":"NORTE VISION CA","Provider Family":"multitel-nortevision.com","RIR Country Code":"VE","Country Name":"Venezuela","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"38.67","ipapi Rank":"543","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #543 with 38.67% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274212","ASN Number":"274212","Network Name":"AS274212 - TELECABLE SPA","Aliases":"TELECABLE SPA","Provider Family":"telecable.cl","RIR Country Code":"CL","Country Name":"Chile","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"17.97","ipapi Rank":"739","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #739 with 17.97% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274227","ASN Number":"274227","Network Name":"AS274227 - MOSSO MAYRA ADELA (INTERZONA FORMOSA)","Aliases":"MOSSO MAYRA ADELA (INTERZONA FORMOSA)","Provider Family":"interzonafsa.com","RIR Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"23.44","ipapi Rank":"646","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #646 with 23.44% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"1","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"AR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274252","ASN Number":"274252","Network Name":"AS274252 - ORELTELECOM S.A.S.","Aliases":"ORELTELECOM S.A.S.","Provider Family":"ajcomputacion.com","RIR Country Code":"EC","Country Name":"Ecuador","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"28.91","ipapi Rank":"589","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #589 with 28.91% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274326","ASN Number":"274326","Network Name":"AS274326 - INTERNET AVALO SUA SRL","Aliases":"INTERNET AVALO SUA SRL","Provider Family":"suareznetwork.com","RIR Country Code":"DO","Country Name":"Dominican Republic","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.14","ipapi Rank":"707","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #707 with 19.14% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274406","ASN Number":"274406","Network Name":"AS274406 - JUAN CARLOS CRUZ MUNOZ","Aliases":"JUAN CARLOS CRUZ MU*OZ","Provider Family":"","RIR Country Code":"MX","Country Name":"Mexico","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.63","ipapi Rank":"802","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #802 with 15.63% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274471","ASN Number":"274471","Network Name":"AS274471 - Wifi net servicos de telecomunicacoes","Aliases":"Wifi net serviços de telecomunicaçõ","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.28","ipapi Rank":"903","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #903 with 13.28% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274714","ASN Number":"274714","Network Name":"AS274714 - Net-Agro Servicos de Comunicacao LTDA","Aliases":"Net-Agro Serviços de Comunicação LTDA","Provider Family":"netagro.net.br","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.67","ipapi Rank":"888","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #888 with 13.67% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274762","ASN Number":"274762","Network Name":"AS274762 - MOBILELINK PROVEDOR DE SERVICOS DE INTERNET LTDA","Aliases":"MOBILELINK PROVEDOR DE SERVICOS DE","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"19.53","ipapi Rank":"698","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #698 with 19.53% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274894","ASN Number":"274894","Network Name":"AS274894 - TV GAITAN TELECOMUNICACIONES SAS","Aliases":"TV GAITAN TELECOMUNICACIONES SAS","Provider Family":"unicomnet.co","RIR Country Code":"CO","Country Name":"Colombia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.89","ipapi Rank":"929","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #929 with 12.89% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274898","ASN Number":"274898","Network Name":"AS274898 - PEREZ CRISTIAN LEANDRO","Aliases":"PEREZ CRISTIAN LEANDRO","Provider Family":"cyberuno.com.ar","RIR Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.23","ipapi Rank":"821","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #821 with 15.23% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS274921","ASN Number":"274921","Network Name":"AS274921 - ARMOA BLANCA NOELIA","Aliases":"ARMOA BLANCA NOELIA","Provider Family":"inetrenzo.com.ar","RIR Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"30.86","ipapi Rank":"580","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #580 with 30.86% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS275640","ASN Number":"275640","Network Name":"AS275640 - Headers Consultoria","Aliases":"Headers Consultoria","Provider Family":"","RIR Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"23.24","ipapi Rank":"648","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #648 with 23.24% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"BR:1"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS327991","ASN Number":"327991","Network Name":"Megasurf Wireless Internet CC - Megasurf Wireless Internet CC","Aliases":"Megasurf Wireless Internet CC","Provider Family":"","RIR Country Code":"ZA","Country Name":"South Africa","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"afrinic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"33.11","ipapi Rank":"570","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #570 with 33.11% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"111","IPsum IPs":"110","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"ZA:111"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS329130","ASN Number":"329130","Network Name":"TAQNYAT ALJEEL COMPANY FOR COMMUNICATION AND INFORMATION TECHNOLOGY LTD - TAQNYAT ALJEEL COMPANY FOR COMMUNICATION AND INFORMATION TECHNOLOGY LTD","Aliases":"TAQNYAT ALJEEL COMPANY FOR COMMUNICATION","Provider Family":"aljeel.ly","RIR Country Code":"LY","Country Name":"Libya","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"afrinic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-11","Source IDs":"S03, N01","Evidence Summary":"This ASN appeared in the High band at rank #970 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"2","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"2","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"LY:2"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS329409","ASN Number":"329409","Network Name":"JIJI FIBER LTD - JIJI FIBER LTD","Aliases":"JIJI FIBER LTD","Provider Family":"","RIR Country Code":"KE","Country Name":"Kenya","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"afrinic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.41","ipapi Rank":"787","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #787 with 16.41% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS329437","ASN Number":"329437","Network Name":"VENNET SOLUTIONS LIMITED - VENNET SOLUTIONS LIMITED","Aliases":"VENNET SOLUTIONS LIMITED","Provider Family":"veenet.africa","RIR Country Code":"KE","Country Name":"Kenya","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"afrinic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"14.69","ipapi Rank":"839","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #839 with 14.69% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"3","Current Listed IPs":"6","IPsum IPs":"1","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"5","Data-Shield IPs":"1","Talos 2024 IPs":"0","Multi-list IPs":"1","Listed-IP Country Mix":"KE:6"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS329618","ASN Number":"329618","Network Name":"Mpaps Internet Solution Limited - Mpaps Internet Solution Limited","Aliases":"Mpaps Internet Solution Limited","Provider Family":"mpaps.co.ke","RIR Country Code":"KE","Country Name":"Kenya","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"afrinic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"16.5","ipapi Rank":"782","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #782 with 16.5% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS394711","ASN Number":"394711","Network Name":"KORGRID - KorGrid, LLC","Aliases":"LIMENET (historical)","Provider Family":"KorGrid","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Historical LIMENET evidence; current-holder continuity unresolved","Evidence Level":"Historical only","FP Risk":"Critical","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"Historical ransomware malvertising and brute-force infrastructure","Last Evidence":"2026-09-15","Source IDs":"N19, N35, N37, N01","Evidence Summary":"Censys described historical LIMENET AS394711 as a known bulletproof-hosting monolith; Rapid7 and time-matched Cisco Talos data add historical abuse context. The current holder is KORGRID / KorGrid LLC. Continuity or reassignment is unresolved, so the BPH label is not carried to the current holder and the row remains disabled.","Analyst Notes":"Historical time-matched Talos mapping: 174 IPs across 15 /24s. Revalidate identity continuity before changing tier.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS396126","ASN Number":"396126","Network Name":"TUCAN - TRANS UNION OF CANADA, INC.","Aliases":"TRANS UNION OF CANADA, INC.","Provider Family":"transunion.com","RIR Country Code":"CA","Country Name":"Canada","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.5","ipapi Rank":"961","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #961 with 12.5% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS396507","ASN Number":"396507","Network Name":"EMERALD-ONION - Emerald Onion","Aliases":"Emerald Onion","Provider Family":"emeraldonion.org","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"21.58","ipapi Rank":"665","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #665 with 21.58% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"2","Current Listed IPs":"97","IPsum IPs":"97","IPsum Score >=3":"3","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"79","Talos 2024 IPs":"0","Multi-list IPs":"79","Listed-IP Country Mix":"US:97"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS396982","ASN Number":"396982","Network Name":"GOOGLE-CLOUD-PLATFORM - Google LLC","Aliases":"","Provider Family":"Google Cloud","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Broad cloud/CDN control row","Evidence Level":"Context","FP Risk":"Very High","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-15","Source IDs":"N01","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Analyst Notes":"Community-feed counts are informational and do not determine this tier.","Current Community Feed Count":"3","Current Listed IPs":"18089","IPsum IPs":"6122","IPsum Score >=3":"1861","IPsum Score >=5":"385","Open-Proxy IPs":"183","Data-Shield IPs":"14034","Talos 2024 IPs":"0","Multi-list IPs":"2249","Listed-IP Country Mix":"US:7370, BE:3116, NL:783, GB:753, JP:689, TW:654, SG:476, DE:475"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS398324","ASN Number":"398324","Network Name":"CENSYS-ARIN-01 - Censys, Inc.","Aliases":"Censys, Inc.","Provider Family":"censys.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"112","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #112 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"1185","IPsum IPs":"1185","IPsum Score >=3":"460","IPsum Score >=5":"255","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"US:1185"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS398705","ASN Number":"398705","Network Name":"CENSYS-ARIN-02 - Censys, Inc.","Aliases":"Censys, Inc.","Provider Family":"censys.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"175","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #175 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"305","IPsum IPs":"305","IPsum Score >=3":"26","IPsum Score >=5":"16","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"US:256, DE:49"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS398722","ASN Number":"398722","Network Name":"CENSYS-ARIN-03 - Censys, Inc.","Aliases":"Censys, Inc.","Provider Family":"censys.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"100","ipapi Rank":"196","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #196 with 100% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"337","IPsum IPs":"337","IPsum Score >=3":"108","IPsum Score >=5":"68","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"HK:337"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS399566","ASN Number":"399566","Network Name":"BIGCOMMERCE - Bigcommerce Inc.","Aliases":"Bigcommerce Inc.","Provider Family":"bigcommerce.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"15.04","ipapi Rank":"829","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #829 with 15.04% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"256","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"256","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"US:256"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS401401","ASN Number":"401401","Network Name":"UNREDACTED-NOISENET - Unredacted Inc","Aliases":"Unredacted Inc","Provider Family":"unredacted.org","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"98.05","ipapi Rank":"467","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #467 with 98.05% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"1","Current Listed IPs":"123","IPsum IPs":"123","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":"US:123"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS401560","ASN Number":"401560","Network Name":"ONECABLE - OneCable Network LLC","Aliases":"OneCable Network LLC","Provider Family":"onecablenetwork.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Isp","Category":"High-abuse isp review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"13.52","ipapi Rank":"896","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this isp ASN #896 with 13.52% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS401661","ASN Number":"401661","Network Name":"EMBNEX-AS - EMBNEX, LLC","Aliases":"","Provider Family":"embnex.com","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Business","Category":"High-abuse business review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"Very High","Abuse %":"20.7","ipapi Rank":"677","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-09-29","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this business ASN #677 with 20.7% observed abuse concentration (Very High) on 2026-09-29.","Analyst Notes":"Disabled because ISP, business, government, banking and education networks can contain legitimate users. ARIN now reports this ASN assigned to EMBNEX, LLC; the earlier reserved/unassigned anomaly is resolved.","Current Community Feed Count":"2","Current Listed IPs":"256","IPsum IPs":"256","IPsum Score >=3":"62","IPsum Score >=5":"2","Open-Proxy IPs":"0","Data-Shield IPs":"78","Talos 2024 IPs":"0","Multi-list IPs":"78","Listed-IP Country Mix":"BR:256"},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS402170","ASN Number":"402170","Network Name":"Valor Holdings LLC","Aliases":"","Provider Family":"valornode.net","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Not currently originating","Route Last Seen":"2026-10-08","Network Type":"Hosting","Category":"Current abuse-concentration hosting review candidate","Evidence Level":"Medium","FP Risk":"Very High","Recommended Use":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling.","Spamhaus ASN-DROP":"No","Abuse Band":"High","Abuse %":"12.5","ipapi Rank":"954","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-09","Source IDs":"S03, N01","Evidence Summary":"ipapi.is ranks this hosting ASN #954 with 12.5% observed abuse concentration (High) on 2026-09-29.","Analyst Notes":"Vendor concentration is a prioritization signal, not malicious-login probability or provider complicity. Routing re-verified 2026-10-09: no announced prefixes on two passes, last seen 2026-10-08. Held for lifecycle review; not removed on a days-old absence.","Current Community Feed Count":"0","Current Listed IPs":"0","IPsum IPs":"0","IPsum Score >=3":"0","IPsum Score >=5":"0","Open-Proxy IPs":"0","Data-Shield IPs":"0","Talos 2024 IPs":"0","Multi-list IPs":"0","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS211443","ASN Number":"211443","Network Name":"SINOWORLDWIDE SINO WORLDWIDE TRADING LIMITED","Aliases":"SINO WORLDWIDE TRADING LIMITED; SINOWORLDWIDE","Provider Family":"sinoworldwidetrading.com","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-07","Source IDs":"S01, S02, N01, N62","Evidence Summary":"Listed in the 2026-10-07 Spamhaus ASN-DROP snapshot as SINOWORLDWIDE (sinoworldwidetrading.com). Registered 2025-11-27. 85.11.187.8, which the FBI and USSS FortiBleed advisory names as the Hashtopolis password-cracking host, is now originated by this ASN; during the June to July 2026 activity its prefix was originated by AS211486.","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS32167","ASN Number":"32167","Network Name":"LSHIY-USER-CONTENT - LSHIY LLC","Aliases":"LSHIY-USER-CONTENT; LSHIY LLC; sibling AS955","Provider Family":"LSHIY LLC","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Campaign watch","Evidence Level":"High for the campaign; weak for ASN-wide use","FP Risk":"High","Recommended Use":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"LSHIY password spray (Azure CLI / ROPC against Entra ID)","Last Evidence":"2026-07-02","Source IDs":"X008, N01","Evidence Summary":"Huntress attributed most of an Entra ID password and token spray, 81 million login attempts and 78 compromised accounts across 64 organizations between 2026-06-12 and 2026-06-26, to 2a0a:d683::/32 originated by AS32167. On 2026-07-02 LSHIY told Huntress the abuser was a bring-your-own-IP customer and suspended it. The operators moved to FranTech AS53667 and then 3xK AS200373, both already catalogued.","Analyst Notes":"Campaign watch: 1 campaign (X008). T3 until 2026-12-29. 2a0a:d683::/32 is no longer routed, so the abusing customer is gone; that is why this is T3 and not T2. Sibling AS955 is named by Huntress only as LSHIY's second ASN, not as a source, and is not catalogued.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS213250","ASN Number":"213250","Network Name":"ITP-SOLUTIONS Dominic Scholz trading as ITP-Solutions GmbH & Co. KG","Aliases":"","Provider Family":"ITP-Solutions","RIR Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Campaign watch","Evidence Level":"High for the campaign; weak for ASN-wide use","FP Risk":"High","Recommended Use":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Storm-3168 compromised service principals","Last Evidence":"2026-09-25","Source IDs":"N52, N01","Evidence Summary":"Microsoft published 45.131.66.106 as a Storm-3168 source for App Service probing and malicious Azure Resource Manager requests made with compromised service principals. 45.131.66.0/23 was originated by AS213250 during the activity and still is.","Analyst Notes":"Campaign watch: 1 campaign (N52). T3 until 2027-03-24. Service-principal sign-ins, not interactive users. Check the service principal sign-in log.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS19318","ASN Number":"19318","Network Name":"IS-AS-1 - Interserver, Inc","Aliases":"","Provider Family":"Interserver","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Campaign watch","Evidence Level":"High for the campaign; weak for ASN-wide use","FP Risk":"High","Recommended Use":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Storm-3168 compromised service principals","Last Evidence":"2026-09-25","Source IDs":"N52, N01","Evidence Summary":"Microsoft published 64.20.53.230 as a Storm-3168 source for App Service probing. 64.20.32.0/19 was originated by AS19318 during the activity and still is.","Analyst Notes":"Campaign watch: 1 campaign (N52). T3 until 2027-03-24. Large commodity US VPS provider, so false positives are likely. Service-principal sign-ins, not interactive users.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS212171","ASN Number":"212171","Network Name":"Local-as Local NCC Ltd.","Aliases":"","Provider Family":"Local NCC","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Campaign watch","Evidence Level":"High for the campaign; weak for ASN-wide use","FP Risk":"High","Recommended Use":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"FortiBleed FortiGate SSL-VPN brute force","Last Evidence":"2026-10-06","Source IDs":"N62, N01","Evidence Summary":"The FBI and USSS FortiBleed advisory lists 185.199.199.56 (observed 2026-06-25) among IPs conducting brute force or authenticating with compromised accounts. 185.199.196.0/22 was originated by AS212171 during the activity and is now originated by AS213929.","Analyst Notes":"Campaign watch: 1 campaign (N62). T3 until 2027-04-04. Watched with AS213929 because the prefix moved.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS213929","ASN Number":"213929","Network Name":"UP-NETWORK UP-NETWORK Sarl","Aliases":"","Provider Family":"UP-NETWORK","RIR Country Code":"CH","Country Name":"Switzerland","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Campaign watch","Evidence Level":"High for the campaign; weak for ASN-wide use","FP Risk":"High","Recommended Use":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"FortiBleed FortiGate SSL-VPN brute force","Last Evidence":"2026-10-06","Source IDs":"N62, N01","Evidence Summary":"Current origin of 185.199.196.0/22, which held 185.199.199.56 when the FBI and USSS observed it in FortiBleed brute force on 2026-06-25 under AS212171.","Analyst Notes":"Campaign watch: 1 campaign (N62). T3 until 2027-04-04. Carrier of the prefix now, not at the time. Watched because operators tend to move with their prefixes.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS210328","ASN Number":"210328","Network Name":"ALMAZ AO ALMAZ","Aliases":"","Provider Family":"AO ALMAZ","RIR Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Campaign watch","Evidence Level":"High for the campaign; weak for ASN-wide use","FP Risk":"High","Recommended Use":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"FortiBleed FortiGate SSL-VPN brute force","Last Evidence":"2026-10-06","Source IDs":"N62, N01","Evidence Summary":"Current origin of 185.136.15.0/24. The FBI and USSS observed 185.136.15.43 and 185.136.15.66 in FortiBleed brute force from 2026-06-27 to 2026-07-23, when the prefix was originated by ASN-DROP listed AS205997, which stopped originating in August.","Analyst Notes":"Campaign watch: 1 campaign (N62). T3 until 2027-04-04. Two prefixes only. Carrier of the prefix now, not at the time.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS201002","ASN Number":"201002","Network Name":"PebbleHost-Customers PebbleHost Ltd","Aliases":"","Provider Family":"PebbleHost","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Campaign watch","Evidence Level":"High for the campaign; weak for ASN-wide use","FP Risk":"High","Recommended Use":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"FortiBleed FortiGate SSL-VPN brute force","Last Evidence":"2026-10-06","Source IDs":"N62, N01","Evidence Summary":"The FBI and USSS observed 193.8.186.33 in FortiBleed brute force from 2026-06-18 to 2026-07-20. 193.8.186.0/24 was originated by AS201002 then and now.","Analyst Notes":"Campaign watch: 1 campaign (N62). T3 until 2027-04-04. Game-server and VPS host.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS267784","ASN Number":"267784","Network Name":"AS267784 - Flyservers S.A.","Aliases":"","Provider Family":"Flyservers","RIR Country Code":"PA","Country Name":"Panama","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"lacnic","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Bulletproof / high-risk hosting family","Category":"Campaign watch","Evidence Level":"High for the campaign; weak for ASN-wide use","FP Risk":"High","Recommended Use":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"FortiBleed FortiGate SSL-VPN brute force","Last Evidence":"2026-10-06","Source IDs":"N62, N01","Evidence Summary":"The FBI and USSS observed 45.227.254.210 in FortiBleed brute force from 2026-06-18 to 2026-07-23. 45.227.254.0/24 was originated by AS267784 then and now. Sibling of Flyservers AS209588, already T2 High.","Analyst Notes":"Campaign watch: 1 campaign (N62). T3 until 2027-04-04. Held at T3 under the campaign-watch rule; the family's T2 sibling stays as it is.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS400940","ASN Number":"400940","Network Name":"RAILWAY - Railway","Aliases":"","Provider Family":"Railway","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"arin","RIR Resource Status":"assigned","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch ended; retained for history","Evidence Level":"High for the campaign; weak for ASN-wide use","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"EvilTokens device-code phishing and M365 token replay","Last Evidence":"2026-04-06","Source IDs":"N58, N59, N01","Evidence Summary":"Huntress tied a device-code phishing and token replay campaign against 344 organizations, 2026-02-19 to mid-March 2026, to Railway PaaS ranges 162.220.232.0/22 and 162.220.234.0/22, with 162.220.234.41 the dominant token engine. Microsoft listed both ranges as threat actor infrastructure observed with sign-in on 2026-04-06.","Analyst Notes":"Campaign watch ended 2026-10-03: 1 campaign (N58, N59), newest report 2026-04-06. Added 2026-10-07 for history. Huntress and Microsoft reported the same device-code campaign, which counts as one. Developer PaaS with heavy legitimate use.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS61046","ASN Number":"61046","Network Name":"HZ-UK-AS HZ Hosting Ltd","Aliases":"","Provider Family":"HZ-UK-AS HZ Hosting Ltd","RIR Country Code":"BG","Country Name":"Bulgaria","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Shared hosting / VPS / cloud","Category":"Campaign watch","Evidence Level":"High for the campaign; weak for ASN-wide use","FP Risk":"High","Recommended Use":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"AI-enabled device-code phishing","Last Evidence":"2026-04-06","Source IDs":"N59, N01","Evidence Summary":"Microsoft listed 185.81.113.0 (HZ Hosting) as threat actor infrastructure observed with sign-in. 185.81.112.0/23 is originated by AS61046.","Analyst Notes":"Campaign watch: 3 campaigns across the HZ Hosting family (N07, N06, N59). T2 until 2026-10-03. T3 until 2027-04-01. Moved T4 to T3 on 2026-10-07 when the ladder was applied retroactively. Sibling HZ Hosting ASNs AS59711 and AS202015 are T2 High on older evidence; the same Microsoft report also names 89.150.45.0 under AS59711.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS43350","ASN Number":"43350","Network Name":"NFORCE NForce Entertainment B.V.","Aliases":"","Provider Family":"NForce","RIR Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Campaign watch ended; retained for history","Evidence Level":"High for the campaign; weak for ASN-wide use","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Palo Alto GlobalProtect login brute force","Last Evidence":"2025-12-04","Source IDs":"N60, N01","Evidence Summary":"GreyNoise attributed most of over 9 million GlobalProtect login sessions, late September to mid-October 2025, to four ASNs including AS43350.","Analyst Notes":"Campaign watch ended 2026-06-02: 1 campaign (N60), newest report 2025-12-04. Added 2026-10-07 for history. GreyNoise describes these ASNs as not generally associated with malicious infrastructure.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS215929","ASN Number":"215929","Network Name":"datacampus Data Campus Limited","Aliases":"","Provider Family":"Data Campus","RIR Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Campaign watch ended; retained for history","Evidence Level":"High for the campaign; weak for ASN-wide use","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Palo Alto GlobalProtect login brute force","Last Evidence":"2025-12-04","Source IDs":"N60, N01","Evidence Summary":"GreyNoise attributed most of over 9 million GlobalProtect login sessions, late September to mid-October 2025, to four ASNs including AS215929.","Analyst Notes":"Campaign watch ended 2026-06-02: 1 campaign (N60), newest report 2025-12-04. Added 2026-10-07 for history. GreyNoise describes these ASNs as not generally associated with malicious infrastructure.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS211632","ASN Number":"211632","Network Name":"ORG-ISI14-RIPE Internet Solutions & Innovations LTD.","Aliases":"","Provider Family":"Internet Solutions & Innovations","RIR Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Campaign watch ended; retained for history","Evidence Level":"High for the campaign; weak for ASN-wide use","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Palo Alto GlobalProtect login brute force","Last Evidence":"2025-12-04","Source IDs":"N60, N01","Evidence Summary":"GreyNoise attributed most of over 9 million GlobalProtect login sessions, late September to mid-October 2025, to four ASNs including AS211632.","Analyst Notes":"Campaign watch ended 2026-06-02: 1 campaign (N60), newest report 2025-12-04. Added 2026-10-07 for history. GreyNoise describes these ASNs as not generally associated with malicious infrastructure.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS214238","ASN Number":"214238","Network Name":"iwihost HOST TELECOM LTD","Aliases":"","Provider Family":"HOST TELECOM","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Commercial VPN / hosting / proxy","Category":"Campaign watch ended; retained for history","Evidence Level":"High for the campaign; weak for ASN-wide use","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Tycoon 2FA AiTM operator logins","Last Evidence":"2026-04-01","Source IDs":"N10, N01","Evidence Summary":"eSentire saw post-takedown Tycoon 2FA Microsoft 365 login attempts from AS214238, and ProxyLine use through it in Gmail-targeted campaigns since at least February 2026.","Analyst Notes":"Campaign watch ended 2026-09-28: 1 campaign (N10), newest report 2026-04-01. Added 2026-10-07 for history. Proxy-service infrastructure.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS204957","ASN Number":"204957","Network Name":"GREENFLOID-AS ROUTE 95 LLC","Aliases":"","Provider Family":"GREEN FLOID","RIR Country Code":"US","Country Name":"United States","Geography Scope":"US","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Campaign watch ended; retained for history","Evidence Level":"High for the campaign; weak for ASN-wide use","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Tycoon 2FA AiTM operator logins","Last Evidence":"2026-04-01","Source IDs":"N10, N01","Evidence Summary":"eSentire saw post-takedown Tycoon 2FA Microsoft 365 login attempts from AS204957.","Analyst Notes":"Campaign watch ended 2026-09-28: 1 campaign (N10), newest report 2026-04-01. Added 2026-10-07 for history. Registered to ROUTE 95 LLC.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T3 Context","ASN":"AS215540","ASN Number":"215540","Network Name":"GCS-AS GLOBAL CONNECTIVITY SOLUTIONS LLP","Aliases":"","Provider Family":"Global Connectivity Solutions","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Hosting / VPS / proxy","Category":"Campaign watch","Evidence Level":"High for the campaign; weak for ASN-wide use","FP Risk":"High","Recommended Use":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Tycoon 2FA AiTM operator logins; Akira ransomware targeting SonicWall SSL VPN","Last Evidence":"2026-04-01","Source IDs":"N10, N06, N01","Evidence Summary":"eSentire saw pre-takedown Tycoon 2FA Microsoft 365 login attempts from AS215540. 185.168.208.102, an Akira SonicWall VPN client IP published by Arctic Wolf in 2025, is now originated by AS215540.","Analyst Notes":"Campaign watch: 2 campaigns (N06, N10). T2 until 2026-09-28. T3 until 2027-03-27. Moved T4 to T3 on 2026-10-07 when the ladder was applied retroactively. Two separate identity campaigns.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"No","Default Enabled":"No","Tier":"T4 Review","ASN":"AS35758","ASN Number":"35758","Network Name":"HQSERV_NETWORKS Rachamim Aviel Twito","Aliases":"","Provider Family":"HQSERV","RIR Country Code":"IL","Country Name":"Israel","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Commercial VPN / hosting / proxy","Category":"Campaign watch ended; retained for history","Evidence Level":"High for the campaign; weak for ASN-wide use","FP Risk":"Very High","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Spamhaus ASN-DROP":"No","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"Yes","Actor / Campaign":"Iran-nexus Microsoft 365 password spray","Last Evidence":"2026-03-31","Source IDs":"N61, N01","Evidence Summary":"Check Point reported Microsoft 365 password spray waves on 2026-03-03, 03-13 and 03-23 against Israel and the UAE using commercial VPN nodes hosted at AS35758, including Windscribe exits geolocated in Israel.","Analyst Notes":"Campaign watch ended 2026-09-27: 1 campaign (N61), newest report 2026-03-31. Added 2026-10-07 for history. Commercial VPN exits; the provider is not the actor.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS198636","ASN Number":"198636","Network Name":"CAPSULA-AS CAPSULA LTD","Aliases":"CAPSULA LTD; CAPSULA-AS","Provider Family":"capsulaltd.uk","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-09","Source IDs":"S01, S02, N01","Evidence Summary":"Listed in the 2026-10-09 Spamhaus ASN-DROP snapshot as CAPSULA-AS (capsulaltd.uk). Registered 2023-05-04.","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS199457","ASN Number":"199457","Network Name":"SolidCore SolidCore Hosting LTD","Aliases":"SolidCore Hosting LTD; SolidCore","Provider Family":"solidserver.io","RIR Country Code":"VG","Country Name":"British Virgin Islands","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-09","Source IDs":"S01, S02, N01","Evidence Summary":"Listed in the 2026-10-09 Spamhaus ASN-DROP snapshot as SolidCore (solidserver.io). Registered 2026-04-02.","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""},{"Effective Enabled":"Yes","Default Enabled":"Yes","Tier":"T1 Critical","ASN":"AS199804","ASN Number":"199804","Network Name":"TFES-AS THE FIRST EAST STAR LTD","Aliases":"THE FIRST EAST STAR LTD; TFES-AS","Provider Family":"the-first-east-star","RIR Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Provider Legal Country":"","RIR":"ripencc","RIR Resource Status":"allocated","Route Status":"Announced","Route Last Seen":"","Network Type":"Mixed / not independently classified","Category":"Current Spamhaus ASN-DROP","Evidence Level":"High","FP Risk":"Medium","Recommended Use":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.","Spamhaus ASN-DROP":"Yes","Abuse Band":"","Abuse %":"","ipapi Rank":"","Login / Identity Evidence":"No","Actor / Campaign":"","Last Evidence":"2026-10-09","Source IDs":"S01, S02, N01","Evidence Summary":"Listed in the 2026-10-09 Spamhaus ASN-DROP snapshot as TFES-AS (the-first-east-star). Registered 2026-03-20.","Analyst Notes":"Current feed membership is high-confidence network risk, not proof that every address or customer is malicious.","Current Community Feed Count":"","Current Listed IPs":"","IPsum IPs":"","IPsum Score >=3":"","IPsum Score >=5":"","Open-Proxy IPs":"","Data-Shield IPs":"","Talos 2024 IPs":"","Multi-list IPs":"","Listed-IP Country Mix":""}],"provider_evidence":[{"ASN":"AS33993","Organization":"UFO-AS UFO Hosting LLC","Aliases":"UFO Hosting; Stark successor; PQ.Hosting successor; UFO-AS","Category":"Sanctioned threat-activity-enabler successor (active)","Route Status":"Announced","Default Tier":"T1 Critical","Enabled":"Yes","Actors / Campaigns":"Russian state-sponsored operations; Iranian state-sponsored operations; DPRK operations; Chinese state-sponsored operations; Doppelgänger; cybercrime infrastructure","Evidence Summary":"Recorded Future assessed with high confidence that UFO Hosting/AS33993 was established or repurposed as a sanctions-resilient vehicle for Stark Industries/PQ.Hosting infrastructure after the EU designation. The current Spamhaus ASN-DROP feed identifies its domain as stark-industries.solutions.","Evidence Date":"2025-08-27","FP Risk":"Medium","Provider Role Assessment":"Source-supported provider or enabler assessment. It does not imply every customer or address is malicious.","Confidence Reason":"High for successor/control relationship and threat-actor-enabler status; label is TAE rather than asserting that every customer is malicious.","Current Status Note":"Active and announcing routes as UFO Hosting LLC on 2026-09-15; present in the current Spamhaus ASN-DROP snapshot.","Source IDs":"S01, S02, S05, S12, S13"},{"ASN":"AS36680","Organization":"NETIFACELLC - Netiface LLC","Aliases":"Netiface; netiface.co.uk","Category":"Source-confirmed BPH (active)","Route Status":"Not currently originating","Default Tier":"T1 Critical","Enabled":"Yes","Actors / Campaigns":"bulletproof hosting","Evidence Summary":"Spamhaus explicitly described Netiface/AS36680 as a bulletproof hoster during an investigation of abuse-resilient infrastructure, and the ASN is in the current ASN-DROP feed.","Evidence Date":"2026-08-24","FP Risk":"Low-Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High: direct provider-level BPH wording from Spamhaus plus live ASN-DROP membership.","Current Status Note":"Active and announcing routes as Netiface LLC on 2026-09-15; present in current ASN-DROP.","Source IDs":"S01, S02, X073"},{"ASN":"AS51396","Organization":"PFCLOUD Pfcloud UG (haftungsbeschrankt)","Aliases":"PFCLOUD; pfcloud.io","Category":"BPH facilitator / upstream risk (active)","Route Status":"Announced","Default Tier":"T1 Critical","Enabled":"Yes","Actors / Campaigns":"upstream/facilitation for proliferating BPH networks","Evidence Summary":"Spamhaus described Pfcloud and aurologic as known in anti-abuse circles for persistent proliferation of bulletproof hosts. AS51396 is also present in the live ASN-DROP feed; this row labels facilitation/uplink risk rather than asserting Pfcloud owns every downstream BPH.","Evidence Date":"2026-08-24","FP Risk":"Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High for current feed status and facilitation role; deliberately narrower than provider-level criminal attribution.","Current Status Note":"Active and announcing routes as Pfcloud UG on 2026-09-15; present in current ASN-DROP.","Source IDs":"S01, S02, S05, X053, X054, X076"},{"ASN":"AS62240","Organization":"Clouvider Clouvider Limited","Aliases":"","Category":"Repeated identity, VPN, ransomware, and C2 infrastructure","Route Status":"Announced","Default Tier":"T1 Critical","Enabled":"Yes","Actors / Campaigns":"Local compromise; Proofpoint; Tycoon 2FA; TAG-53; Akira; Fog; ToolShell","Evidence Summary":"Clouvider AS62240 is legitimate global hosting, transit, and proxy-exit infrastructure repeatedly used for credential replay, phishing authentication, malicious VPN access, ransomware access, and C2. The requester also reported a local 2026 compromise. This supports high-priority monitoring, not a claim of provider complicity.","Evidence Date":"2026-09-15","FP Risk":"Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High for repeated use, but no evidence of provider complicity","Current Status Note":"Immediate triage for successful interactive employee sign-ins. Correlate new device, MFA or passkey changes, token behavior, VPN access, session anomalies, and post-authentication activity before containment.","Source IDs":"S04, S06, N06, N07, N08, N09, N10, N11, N12, N13, N14, N16, N34"},{"ASN":"AS138915","Organization":"KAOPU-HK - Kaopu Cloud HK Limited","Aliases":"KAOPU-HK; Kaopu Cloud","Category":"Current Spamhaus ASN-DROP","Route Status":"Announced","Default Tier":"T1 Critical","Enabled":"Yes","Actors / Campaigns":"","Evidence Summary":"AS138915 is present in the 2026-09-15 Spamhaus ASN-DROP feed. This review did not find a sufficiently authoritative public source tying the entire ASN to Funnull or another named campaign, so no such alias or actor attribution is asserted.","Evidence Date":"2026-09-15","FP Risk":"Low-Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High for current Spamhaus feed membership; unproven as a named BPH-provider attribution in the reviewed public reporting.","Current Status Note":"Active and announcing routes as Kaopu Cloud HK Limited on 2026-09-15. Use the live ASN-DROP feed rather than copying this ASN permanently.","Source IDs":"S01, S02"},{"ASN":"AS154177","Organization":"LIGHT4-AS-AP - LIGHT NODE LIMITED","Aliases":"LIGHT NODE LIMITED; LIGHT4-AS-AP","Category":"Current Spamhaus ASN-DROP","Route Status":"Announced","Default Tier":"T1 Critical","Enabled":"Yes","Actors / Campaigns":"","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as LIGHT4-AS-AP (kaopuyun.com). Current origin of 149.104.78.141, primary-source Citrix exploitation IOC.","Evidence Date":"2026-09-29","FP Risk":"Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High exact IOC and RIPEstat origin; ASN-wide maliciousness rests on existing Spamhaus status","Current Status Note":"Append exact-IP campaign evidence; preserve existing T1 Critical","Source IDs":"S01, S02, N01, S03, N40"},{"ASN":"AS201738","Organization":"UFO-TECHNOLOGIES-LIMITED UFO TECHNOLOGIES LIMITED","Aliases":"Bearhost-linked; changway.hk feed lineage","Category":"Source-confirmed BPH (active)","Route Status":"Announced","Default Tier":"T1 Critical","Enabled":"Yes","Actors / Campaigns":"Bearhost bulletproof-hosting ecosystem","Evidence Summary":"Spamhaus linked AS201738 to the Bearhost threat actor's BPH comeback and confirmed inclusion in DROP/ASN-DROP. The live feed currently associates the ASN with changway.hk.","Evidence Date":"2026-04-29","FP Risk":"Low-Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High: direct BPH/operator linkage by Spamhaus and current block-feed inclusion.","Current Status Note":"Active and announcing routes as UFO TECHNOLOGIES LIMITED on 2026-09-15; present in current ASN-DROP.","Source IDs":"S01, S02, X072"},{"ASN":"AS202412","Organization":"OMEGATECH-AS Omegatech LTD","Aliases":"Virtualine; virtualine.org","Category":"Source-confirmed BPH (active)","Route Status":"Announced","Default Tier":"T1 Critical","Enabled":"Yes","Actors / Campaigns":"bulletproof hosting; botnet command-and-control","Evidence Summary":"Spamhaus identified Virtualine as a BPH operation and the January-June 2026 Spamhaus botnet report ranked it fifth among newly observed networks with 382 C2 observations and seventeenth among active networks. AS202412 remains in ASN-DROP.","Evidence Date":"2025-09-18","FP Risk":"Low-Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High: direct BPH attribution, sustained measured C2 concentration, and current block-feed inclusion.","Current Status Note":"Active and announcing routes as Omegatech LTD on 2026-09-15; present in current ASN-DROP.","Source IDs":"S01, S02, X075"},{"ASN":"AS206728","Organization":"MEDIALAND-AS Media Land LLC","Aliases":"MediaLand; yalishanda; MEDIALAND-AS","Category":"Source-confirmed sanctioned BPH (active)","Route Status":"Announced","Default Tier":"T1 Critical","Enabled":"Yes","Actors / Campaigns":"LockBit; BlackSuit; Play ransomware; phishing; brute-force attacks; malware delivery","Evidence Summary":"Team Cymru maps sanctioned Media Land to AS206728 and found the network continuing to announce infrastructure and host suspicious domains after designation. Treasury described Media Land as a BPH provider supporting ransomware and attacks against U.S. critical infrastructure. Silent Push reports Yalishanda advertising Media Land fast-flux offerings. Missing exact Treasury Nov19 designation is direct official evidence.","Evidence Date":"2026-09-15","FP Risk":"Medium","Provider Role Assessment":"Source-supported provider or enabler assessment. It does not imply every customer or address is malicious.","Confidence Reason":"High: exact ASN mapping, provider-level government designation, and post-designation activity measurement. High provider designation and historical ASN identity; verify current feed/routes separately","Current Status Note":"Active and announcing routes as Media Land LLC on 2026-09-15; present in the current Spamhaus ASN-DROP snapshot. Append official designation source and fresh service-model evidence; preserve T1","Source IDs":"S01, S02, S11, S20, N38, N43"},{"ASN":"AS209847","Organization":"THE WorkTitans B.V.","Aliases":"THE.Hosting; PQ.Hosting successor; Stark successor; THE","Category":"Sanctioned threat-activity-enabler successor (active)","Route Status":"Announced","Default Tier":"T1 Critical","Enabled":"Yes","Actors / Campaigns":"Russian state-sponsored operations; Iranian state-sponsored operations; DPRK operations; Chinese state-sponsored operations; cybercrime infrastructure","Evidence Summary":"Recorded Future documented AS209847 as a newly created network for THE.Hosting, the brand succeeding PQ.Hosting/Stark Industries, and assessed continued operation despite sanctions and ownership changes.","Evidence Date":"2025-08-27","FP Risk":"Medium","Provider Role Assessment":"Source-supported provider or enabler assessment. It does not imply every customer or address is malicious.","Confidence Reason":"High for infrastructure continuity; provider is best treated as a sanctioned threat-actor enabler/successor rather than proof every hosted workload is malicious.","Current Status Note":"Active and announcing routes as WorkTitans B.V. on 2026-09-15; present in the current Spamhaus ASN-DROP snapshot.","Source IDs":"S01, S02, S12, S13"},{"ASN":"AS210558","Organization":"services-1337-gmbh 1337 Services GmbH","Aliases":"1337 Services GmbH; services-1337-gmbh","Category":"Current Spamhaus ASN-DROP","Route Status":"Announced","Default Tier":"T1 Critical","Enabled":"Yes","Actors / Campaigns":"","Evidence Summary":"Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as services-1337-gmbh (as210558.net). Spamhaus H1 newly observed C2 count: 273 under as210558.net.","Evidence Date":"2026-09-29","FP Risk":"Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High report metrics","Current Status Note":"Append anti-abuse report context; no tier change","Source IDs":"S01, S02, N01, S03, N42"},{"ASN":"AS210644","Organization":"AEZA-AS AEZA GROUP LLC","Aliases":"Aeza; AEZA-AS","Category":"Source-confirmed sanctioned BPH (active)","Route Status":"Announced","Default Tier":"T1 Critical","Enabled":"Yes","Actors / Campaigns":"Meduza Stealer; Lumma Stealer; BianLian; RedLine Stealer; BlackSprut; Doppelgänger; DDoSia","Evidence Summary":"Silent Push identifies AS210644 as Aeza bulletproof-hosting infrastructure and documents post-sanctions route migration to Hypercore. U.S. Treasury separately designated Aeza Group for providing BPH to infostealers, ransomware actors and illicit markets.","Evidence Date":"2025-07-24","FP Risk":"Medium","Provider Role Assessment":"Source-supported provider or enabler assessment. It does not imply every customer or address is malicious.","Confidence Reason":"High: the ASN-to-provider mapping is explicit and the provider itself was sanctioned as BPH; this is provider-level evidence, not merely one malicious tenant.","Current Status Note":"Active and announcing routes as Aéza International Limited on 2026-09-15; also present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Revalidate holder and announcements before enforcement.","Source IDs":"S01, S02, S09, S14"},{"ASN":"AS211663","Organization":"GALEON-AS GALEON LLC","Aliases":"Bearhost-linked; changway.hk feed lineage","Category":"Source-confirmed BPH (active)","Route Status":"Announced","Default Tier":"T1 Critical","Enabled":"Yes","Actors / Campaigns":"Bearhost bulletproof-hosting ecosystem","Evidence Summary":"Spamhaus linked AS211663 to the Bearhost threat actor's BPH return and placed it in DROP/ASN-DROP. The live ASN-DROP feed currently associates it with changway.hk.","Evidence Date":"2026-04-29","FP Risk":"Low-Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High: direct BPH/operator linkage by Spamhaus and current block-feed inclusion.","Current Status Note":"Active and announcing routes as GALEON LLC on 2026-09-15; present in current ASN-DROP.","Source IDs":"S01, S02, X072"},{"ASN":"AS214351","Organization":"FEMOIT FEMO IT SOLUTIONS LIMITED","Aliases":"Femo IT Solutions; Defhost-linked; FEMOIT","Category":"Source-confirmed BPH (active)","Route Status":"Announced","Default Tier":"T1 Critical","Enabled":"Yes","Actors / Campaigns":"Cobalt Strike; DcRat; Rhadamanthys; TinyLoader; THC Hydra; Amadey; QuasarRAT; RedLine Stealer; REMCOS; Stealc; SystemBC; SvcStealer; CastleLoader","Evidence Summary":"Recorded Future assessed with high confidence that AS214351 is controlled by Defhost, a service that openly markets resilience to governments, regulators and Spamhaus. The report observed numerous malware and C2 families in its space. Spamhaus H1 active C2 count: 17 under as214351.com.","Evidence Date":"2026-07-10","FP Risk":"Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High: provider-control assessment, abuse-resilience marketing, multiple independent malware families, and current ASN-DROP inclusion collectively exceed one-off rental evidence. High report metrics","Current Status Note":"Active and announcing routes as FEMO IT SOLUTIONS LIMITED on 2026-09-15; present in the current Spamhaus ASN-DROP snapshot. Append anti-abuse report context; no tier change","Source IDs":"S01, S02, S05, X003, X031, N42"},{"ASN":"AS216246","Organization":"RU-AEZA-AS Aeza Group LLC","Aliases":"Aeza; RU-AEZA-AS","Category":"Source-confirmed sanctioned BPH (active)","Route Status":"Announced","Default Tier":"T1 Critical","Enabled":"Yes","Actors / Campaigns":"Meduza Stealer; Lumma Stealer; BianLian; RedLine Stealer; BlackSprut","Evidence Summary":"Silent Push explicitly maps AS216246 to Aeza Group and calls Aeza a sanctioned BPH provider. Treasury described Aeza as supplying infrastructure to malware, ransomware and illicit-drug-market operators.","Evidence Date":"2025-07-24","FP Risk":"Medium","Provider Role Assessment":"Source-supported provider or enabler assessment. It does not imply every customer or address is malicious.","Confidence Reason":"High: explicit ASN mapping plus government provider-level sanctions designation.","Current Status Note":"Active and announcing routes as Aeza Group LLC on 2026-09-15; also present in the current Spamhaus ASN-DROP snapshot.","Source IDs":"S01, S02, S09, S14"},{"ASN":"AS219067","Organization":"CHIARA-AS Chiara Conti","Aliases":"CHIARA-AS; eggywall.org","Category":"Current malicious prefix-hopping network","Route Status":"Announced","Default Tier":"T1 Critical","Enabled":"Yes","Actors / Campaigns":"Roblox credential phishing; prefix hopping","Evidence Summary":"Spamhaus tied AS219067's sole prefix to Roblox phishing, documented deliberate prefix-hopping behavior, and placed the network in SBL/DROP. This is strong malicious-network evidence but not a generalized BPH-provider attribution.","Evidence Date":"2026-08-24","FP Risk":"Low","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High for current malicious operation; category intentionally avoids claiming a broader BPH service without evidence.","Current Status Note":"Active and announcing routes as Chiara Conti/CHIARA-AS on 2026-09-15; present in current ASN-DROP.","Source IDs":"S01, S02, X074"},{"ASN":"AS399979","Organization":"AS-493NETWORKING - 49.3 Networking LLC","Aliases":"AS-493NETWORKING; 493networking.cc","Category":"Source-confirmed BPH (active)","Route Status":"Announced","Default Tier":"T1 Critical","Enabled":"Yes","Actors / Campaigns":"bulletproof hosting; cybercriminal infrastructure","Evidence Summary":"Spamhaus publicly identified AS399979/49.3 Networking as a bulletproof host and described the operator as using a Delaware shell company. The ASN remains in the live ASN-DROP feed.","Evidence Date":"2025-09-26","FP Risk":"Low-Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High: explicit BPH attribution by Spamhaus plus current ASN-DROP inclusion; the ASN announces a very small footprint, reducing carrier-scale collateral risk.","Current Status Note":"Active and announcing routes as 49.3 Networking LLC on 2026-09-15; present in current Spamhaus ASN-DROP.","Source IDs":"S01, S02, X071"},{"ASN":"AS11878","Organization":"TZULO - tzulo, inc.","Aliases":"","Category":"Campaign watch","Route Status":"Announced","Default Tier":"T3 Context","Enabled":"Yes","Actors / Campaigns":"UNC6671","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS11878 across UNC6671 multi-brand vishing, AiTM, and SaaS extortion. This does not implicate the provider or every tenant.","Evidence Date":"2026-08-06","FP Risk":"Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High for exact infrastructure; medium at ASN level","Current Status Note":"Campaign watch: 1 campaign (N17).","Source IDs":"N17, N01"},{"ASN":"AS14956","Organization":"ROUTERHOSTING - RouterHosting LLC","Aliases":"Cloudzy; RouterHosting; Webair Internet Development Inc","Category":"Legacy hosting/VPS watchlist","Route Status":"Announced","Default Tier":"T2 High","Enabled":"Yes","Actors / Campaigns":"","Evidence Summary":"Halcyon reported substantial Cloudzy infrastructure used by ransomware and nation-state C2 and alleged a permissive operating model; Cloudzy disputed those conclusions. JUMPSEC subsequently mapped multiple 2026 DPRK BlueNoroff campaign domains to AS14956. Repeated malicious use is strong; knowing complicity remains disputed. Conditional fast-flux analytic includes AS14956; independent Spamhaus H1 C2 report adds Cloudzy volume context. This is stronger recurring abuse evidence without resolving disputed complicity.","Evidence Date":"2026-09-15","FP Risk":"Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Strong observed misuse; provider complicity disputed","Current Status Note":"Append provider evidence; preserve existing T2 High","Source IDs":"S05, X016, X017, X018, N01, N38, N42"},{"ASN":"AS25369","Organization":"BANDWIDTH-AS Hydra Communications Ltd","Aliases":"","Category":"Campaign watch","Route Status":"Announced","Default Tier":"T3 Context","Enabled":"Yes","Actors / Campaigns":"UNC6671","Evidence Summary":"Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS25369 across UNC6671 multi-brand vishing, AiTM, and SaaS extortion. This does not implicate the provider or every tenant.","Evidence Date":"2026-08-06","FP Risk":"Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High for exact infrastructure; medium at ASN level","Current Status Note":"Campaign watch: 1 campaign (N17).","Source IDs":"N17, N01"},{"ASN":"AS36352","Organization":"AS-COLOCROSSING - HostPapa","Aliases":"","Category":"Campaign watch ended; retained for history","Route Status":"Announced","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"Akira ransomware targeting SonicWall SSL VPN","Evidence Summary":"Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS36352 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant. Current origin of Kapibala exploitation IOC 172.245.247.21. Spamhaus H1 report ranks ColoCrossing #3 newly observed C2, not normalized.","Evidence Date":"2026-09-21","FP Risk":"Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High exact IOC; medium ASN-level relevance","Current Status Note":"Campaign watch ended 2026-03-21: 1 campaign (N06), newest report 2025-09-22.","Source IDs":"N06, N01"},{"ASN":"AS39287","Organization":"materialism Materialism s.r.l.","Aliases":"Njalla","Category":"Phishing-panel backend infrastructure","Route Status":"Announced","Default Tier":"T2 High","Enabled":"Yes","Actors / Campaigns":"Doko-derived panel; UNC6671; BlackFile","Evidence Summary":"Active related network for Njalla. No direct provider-level malicious designation was established; retain as enabled T2 monitoring context and require device, session, event-country, or post-authentication corroboration.","Evidence Date":"2026-09-15","FP Risk":"Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High for exact infrastructure; medium at ASN level","Current Status Note":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Source IDs":"N18, N21"},{"ASN":"AS48721","Organization":"FLYSERVERS-ENDCLIENTS Flyservers S.A.","Aliases":"Flyservers","Category":"Published BPH attribution, older evidence (active)","Route Status":"Announced","Default Tier":"T2 High","Enabled":"Yes","Actors / Campaigns":"adversary command-and-control hosting","Evidence Summary":"Recorded Future's 2022 Adversary Infrastructure Report explicitly listed Flyservers S.A. among known BPH providers and mapped it to AS48721 in its ASN table.","Evidence Date":"2022-12-15","FP Risk":"Medium-High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Medium: provider-level BPH wording is explicit, but the public evidence is older and should be refreshed with current IP/campaign signals.","Current Status Note":"Active and announcing routes as Flyservers S.A. on 2026-09-15. Watch/step-up tier pending fresh corroboration.","Source IDs":"X057"},{"ASN":"AS51852","Organization":"PLI-AS Private Layer INC","Aliases":"","Category":"AiTM reverse-proxy infrastructure","Route Status":"Announced","Default Tier":"T2 High","Enabled":"Yes","Actors / Campaigns":"UNC6671","Evidence Summary":"Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS51852 across UNC6671 multi-brand vishing, AiTM, and SaaS extortion. This does not implicate the provider or every tenant.","Evidence Date":"2026-08-06","FP Risk":"Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High for exact infrastructure; medium at ASN level","Current Status Note":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Source IDs":"N17"},{"ASN":"AS58061","Organization":"SCALAXY-AS Scalaxy B.V.","Aliases":"","Category":"Related provider or broad shared-service context","Route Status":"Announced","Default Tier":"T2 High","Enabled":"Yes","Actors / Campaigns":"","Evidence Summary":"Silent Push included AS58061 in a conditional multi-ASN fast-flux DNS analytic. The source explicitly warns that not every rotating ASN is bulletproof; preserve T2 monitoring but require the full DNS-diversity or identity/behavior context.","Evidence Date":"2026-09-15","FP Risk":"Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High analytic inclusion; low provider maliciousness","Current Status Note":"Enabled as T2 context. Do not treat the ASN alone as a malicious verdict.","Source IDs":"N01, N38"},{"ASN":"AS60117","Organization":"HS Host Sailor Ltd","Aliases":"HostSailor","Category":"Published BPH attribution, older evidence (active)","Route Status":"Announced","Default Tier":"T2 High","Enabled":"Yes","Actors / Campaigns":"adversary command-and-control hosting","Evidence Summary":"Recorded Future's 2022 report described Host Sailor Ltd as a BPH provider observed in adversary infrastructure and mapped it to AS60117.","Evidence Date":"2022-12-15","FP Risk":"High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Medium: explicit provider-level wording but stale public evidence; current posture should be refreshed before punitive action.","Current Status Note":"Active and announcing routes as Host Sailor Ltd on 2026-09-15. Watch tier only without fresher corroboration.","Source IDs":"X057"},{"ASN":"AS136787","Organization":"PACKETHUBSA-AS-AP - PacketHub S.A.","Aliases":"PacketHub S.A.","Category":"Commercial VPN / anonymizer with direct token-replay evidence","Route Status":"Announced","Default Tier":"T2 High","Enabled":"Yes","Actors / Campaigns":"EvilTokens device-code phishing and token replay; NordVPN-associated egress","Evidence Summary":"PacketHub S.A. operates global hosting infrastructure associated with NordVPN exit traffic. Published reporting observed PacketHub infrastructure in token replay, exploitation, and DDoS activity. Monitor unexpected employee logins; there is no evidence of provider complicity.","Evidence Date":"2026-04-06","FP Risk":"Medium-High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High for observed infrastructure; no provider complicity","Current Status Note":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Source IDs":"N15, N29, N30, N31"},{"ASN":"AS141039","Organization":"PACKETHUBSA-AS-AP - PacketHub S.A.","Aliases":"PacketHub S.A.","Category":"Commercial VPN / anonymizer provider family","Route Status":"Announced","Default Tier":"T2 High","Enabled":"Yes","Actors / Campaigns":"NordVPN-associated egress","Evidence Summary":"PacketHub S.A. operates global hosting infrastructure associated with NordVPN exit traffic. Published reporting observed PacketHub infrastructure in token replay, exploitation, and DDoS activity. Monitor unexpected employee logins; there is no evidence of provider complicity.","Evidence Date":"2026-09-15","FP Risk":"Medium-High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Medium provider-family association","Current Status Note":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Source IDs":"N29, N30, N31"},{"ASN":"AS147049","Organization":"PACKETHUBSA-AS-AP - PacketHub S.A.","Aliases":"PacketHub S.A.","Category":"Commercial VPN / anonymizer provider family","Route Status":"Announced","Default Tier":"T2 High","Enabled":"Yes","Actors / Campaigns":"NordVPN-associated egress","Evidence Summary":"PacketHub S.A. operates global hosting infrastructure associated with NordVPN exit traffic. Published reporting observed PacketHub infrastructure in token replay, exploitation, and DDoS activity. Monitor unexpected employee logins; there is no evidence of provider complicity.","Evidence Date":"2026-09-15","FP Risk":"Medium-High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Medium provider-family association","Current Status Note":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Source IDs":"N29, N30, N31"},{"ASN":"AS200651","Organization":"FlokiNET FlokiNET ehf","Aliases":"","Category":"Source-described bulletproof-hosting monolith","Route Status":"Announced","Default Tier":"T2 High","Enabled":"Yes","Actors / Campaigns":"Bulletproof hosting","Evidence Summary":"Censys identifies FlokiNET AS200651 as a widely recognized bulletproof-hosting monolith. Use for monitoring and triage, not unconditional blocking of every customer.","Evidence Date":"2026-09-15","FP Risk":"Medium","Provider Role Assessment":"Source-supported provider or enabler assessment. It does not imply every customer or address is malicious.","Confidence Reason":"High provider-level wording from Censys","Current Status Note":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Source IDs":"N19"},{"ASN":"AS201814","Organization":"Mevspace MEVSPACE sp. z o.o.","Aliases":"","Category":"Phishing-panel backend infrastructure","Route Status":"Announced","Default Tier":"T2 High","Enabled":"Yes","Actors / Campaigns":"UNC6671; Doko Panel; ShinyHunters","Evidence Summary":"Published reporting includes 4 time-bounded indicators attributed to or currently mapped to AS201814 across Doko's Panel / ShinyHunters phishing-panel infrastructure; UNC6671 multi-brand vishing, AiTM, and SaaS extortion; UNC6671 phishing infrastructure. This does not implicate the provider or every tenant.","Evidence Date":"2026-08-06","FP Risk":"Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High for exact infrastructure; medium at ASN level","Current Status Note":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Source IDs":"N17, N18, N21"},{"ASN":"AS207137","Organization":"PACKETHUBSA PacketHub S.A.","Aliases":"PacketHub S.A.","Category":"Commercial VPN / anonymizer provider family","Route Status":"Announced","Default Tier":"T2 High","Enabled":"Yes","Actors / Campaigns":"NordVPN-associated egress","Evidence Summary":"PacketHub S.A. operates global hosting infrastructure associated with NordVPN exit traffic. Published reporting observed PacketHub infrastructure in token replay, exploitation, and DDoS activity. Monitor unexpected employee logins; there is no evidence of provider complicity.","Evidence Date":"2026-09-15","FP Risk":"Medium-High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Medium provider-family association","Current Status Note":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Source IDs":"N29, N30, N31"},{"ASN":"AS209588","Organization":"FLYSERVERS-ASN Flyservers S.A.","Aliases":"Flyservers","Category":"Published BPH attribution, older evidence (active)","Route Status":"Announced","Default Tier":"T2 High","Enabled":"Yes","Actors / Campaigns":"adversary command-and-control hosting","Evidence Summary":"Recorded Future's 2022 report explicitly identified Flyservers S.A. as a known BPH provider and mapped AS209588 to it in the report's ASN table.","Evidence Date":"2022-12-15","FP Risk":"Medium-High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Medium: explicit provider-level classification, tempered by the age of the public report.","Current Status Note":"Active and announcing routes as Flyservers S.A. on 2026-09-15. Watch/step-up tier pending fresh corroboration.","Source IDs":"X057"},{"ASN":"AS272096","Organization":"AS272096 - PACKETHUB S.A.","Aliases":"PacketHub S.A.","Category":"Commercial VPN / anonymizer provider family","Route Status":"Announced","Default Tier":"T2 High","Enabled":"Yes","Actors / Campaigns":"NordVPN-associated egress","Evidence Summary":"PacketHub S.A. operates global hosting infrastructure associated with NordVPN exit traffic. Published reporting observed PacketHub infrastructure in token replay, exploitation, and DDoS activity. Monitor unexpected employee logins; there is no evidence of provider complicity.","Evidence Date":"2026-09-15","FP Risk":"Medium-High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Medium provider-family association","Current Status Note":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.","Source IDs":"N29, N30, N31"},{"ASN":"AS54203","Organization":"NETPROTECT-SP - Strong Technology, LLC.","Aliases":"","Category":"Commercial VPN / proxy egress in campaign-time mapping","Route Status":"Announced","Default Tier":"T3 Context","Enabled":"Yes","Actors / Campaigns":"Cisco Talos 2024 brute force","Evidence Summary":"Time-matched RouteViews mapping attributes 178 IPs across 34 /24s from the Cisco Talos April 2024 brute-force IOC set to this Strong Technology / NetProtect ASN. Treat as commercial VPN/proxy egress context; no provider complicity is asserted.","Evidence Date":"2026-09-15","FP Risk":"Medium-High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Medium; no provider complicity","Current Status Note":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.","Source IDs":"N35, N36"},{"ASN":"AS62651","Organization":"NETPROTECT-DP - Strong Technology, LLC.","Aliases":"","Category":"Commercial VPN / proxy egress in campaign-time mapping","Route Status":"Announced","Default Tier":"T3 Context","Enabled":"Yes","Actors / Campaigns":"Cisco Talos 2024 brute force","Evidence Summary":"Time-matched RouteViews mapping attributes 130 IPs across 37 /24s from the Cisco Talos April 2024 brute-force IOC set to this Strong Technology / NetProtect ASN. Treat as commercial VPN/proxy egress context; no provider complicity is asserted.","Evidence Date":"2026-09-15","FP Risk":"Medium-High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Medium; no provider complicity","Current Status Note":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.","Source IDs":"N35, N36"},{"ASN":"AS204997","Organization":"FIRSTBYTE-AS FIRST SERVER LIMITED","Aliases":"","Category":"Suspicious VM and brute-force infrastructure","Route Status":"Announced","Default Tier":"T3 Context","Enabled":"Yes","Actors / Campaigns":"Brute-force-as-a-service artifacts","Evidence Summary":"Active related network for FIRST SERVER. No direct provider-level malicious designation was established; retain as enabled T3 risk context and require at least one corroborating identity or behavioral anomaly.","Evidence Date":"2026-09-15","FP Risk":"Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Medium; shared infrastructure","Current Status Note":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.","Source IDs":"N19, N22"},{"ASN":"AS205090","Organization":"FIRST-SERVER-EUROPE FIRST SERVER LIMITED","Aliases":"","Category":"Suspicious VM and C2 infrastructure","Route Status":"Announced","Default Tier":"T3 Context","Enabled":"Yes","Actors / Campaigns":"Reverse connection; C2; persistence tooling","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS205090 across Reverse-connection endpoint exposed with C2 and persistence tooling. This does not implicate the provider or every tenant.","Evidence Date":"2026-02-03","FP Risk":"Medium","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Medium; shared infrastructure and current IP mapping changed","Current Status Note":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.","Source IDs":"N19, N22"},{"ASN":"AS12586","Organization":"ASGHOSTNET GHOSTnet GmbH","Aliases":"","Category":"Behavior-correlated enrollment infrastructure","Route Status":"Announced","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"GhostCode","Evidence Summary":"eSentire observed successful final Intune enrollment from 5.230.71.51 on reported AS12586 after device-code token theft.","Evidence Date":"2026-09-15","FP Risk":"High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High for the exact incident endpoint and sequence; low for ASN-wide inference.","Current Status Note":"Disabled by default; use exact-IP and behavior correlation.","Source IDs":"N48"},{"ASN":"AS25820","Organization":"IT7NET - IT7 Networks Inc","Aliases":"","Category":"Point-IOC provider context","Route Status":"Announced","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"","Evidence Summary":"Current origin of Kapibala C2 104.225.153.141. Source-scoped evidence does not establish that the provider or every tenant is malicious.","Evidence Date":"2026-09-21","FP Risk":"High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High exact-IP; low ASN-wide attribution","Current Status Note":"Disabled pending independent or local corroboration.","Source IDs":"N39"},{"ASN":"AS30823","Organization":"AUROLOGIC aurologic GmbH","Aliases":"combahton GmbH; fastpipe.io","Category":"Legitimate upstream carrier, context only","Route Status":"Announced","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"upstream transit for multiple high-risk and malicious networks","Evidence Summary":"Recorded Future found aurologic to be a central upstream providing connectivity to many high-risk networks. The report expressly frames it as a legitimate carrier and does not establish aurologic itself as criminal or bulletproof hosting.","Evidence Date":"2025-11-06","FP Risk":"Very High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High for topology and transit role; insufficient for provider-level maliciousness. This row is a deliberate no-block/context control.","Current Status Note":"Active and announcing routes as aurologic GmbH on 2026-09-15. CONTEXT ONLY-do not put the whole ASN in an identity deny list.","Source IDs":"S05, X003, X031"},{"ASN":"AS49468","Organization":"MAGHOST_RO MAGIT'ST SRL","Aliases":"","Category":"Conditional fast-flux ASN seed","Route Status":"Announced","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"Fast-flux phishing infrastructure","Evidence Summary":"Conditional fast-flux analytic includes this ASN. Source-scoped evidence does not establish that the provider or every tenant is malicious.","Evidence Date":"2026-09-15","FP Risk":"High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High analytic membership, low ASN-wide attribution","Current Status Note":"Disabled pending independent or local corroboration.","Source IDs":"N38"},{"ASN":"AS57523","Organization":"changway-as Chang Way Technologies Co. Limited","Aliases":"Chang Way Technologies; changway-as","Category":"Published BPH attribution (withdrawn)","Route Status":"Not currently originating","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"adversary command-and-control hosting","Evidence Summary":"Recorded Future's 2022 report explicitly named Chang Way Technologies as a known BPH provider and mapped AS57523 to it. Spamhaus still lists the ASN in its 2026-09-15 ASN-DROP snapshot, but it is not currently announcing routes.","Evidence Date":"2022-12-15","FP Risk":"Low","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High historical provider classification; no basis for current enforcement while withdrawn.","Current Status Note":"Not announcing routes on 2026-09-15. Move from active deny/watch logic to a tombstone with holder-change checks.","Source IDs":"S01, S02, S05, X057"},{"ASN":"AS197574","Organization":"EXPRESSHOST ExpressHost Ltd","Aliases":"","Category":"Conditional fast-flux ASN seed","Route Status":"Announced","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"Fast-flux phishing infrastructure","Evidence Summary":"Conditional fast-flux analytic includes this ASN. Source-scoped evidence does not establish that the provider or every tenant is malicious.","Evidence Date":"2026-09-15","FP Risk":"High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High analytic membership, low ASN-wide attribution","Current Status Note":"Disabled pending independent or local corroboration.","Source IDs":"N38"},{"ASN":"AS198550","Organization":"nodehost-as NODE HOST LIMITED","Aliases":"","Category":"Conditional fast-flux ASN seed","Route Status":"Announced","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"Fast-flux phishing infrastructure","Evidence Summary":"Conditional fast-flux analytic includes this ASN. Source-scoped evidence does not establish that the provider or every tenant is malicious.","Evidence Date":"2026-09-15","FP Risk":"High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High analytic membership, low ASN-wide attribution","Current Status Note":"Disabled pending independent or local corroboration.","Source IDs":"N38"},{"ASN":"AS207461","Organization":"host-industry HOSTING INDUSTRY LIMITED","Aliases":"","Category":"Point-IOC provider context","Route Status":"Announced","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"","Evidence Summary":"Current origin of repeated Settra MeshAgent C2 endpoint 193.5.65.114. Source-scoped evidence does not establish that the provider or every tenant is malicious.","Evidence Date":"2026-09-17","FP Risk":"High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High exact-IP incident evidence; medium network inference","Current Status Note":"Independent current abuse concentration or direct successful sign-in campaign evidence required for ASN-wide alert escalation","Source IDs":"N41"},{"ASN":"AS209378","Organization":"INIOS-AS Inios Oy","Aliases":"","Category":"Conditional fast-flux ASN seed","Route Status":"Announced","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"Fast-flux phishing infrastructure","Evidence Summary":"Conditional fast-flux analytic includes this ASN. Source-scoped evidence does not establish that the provider or every tenant is malicious.","Evidence Date":"2026-09-15","FP Risk":"High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High analytic membership, low ASN-wide attribution","Current Status Note":"Disabled pending independent or local corroboration.","Source IDs":"N38"},{"ASN":"AS213511","Organization":"VSVK VSVK Onderhoud B.V.","Aliases":"VSVK; fraudulent RIPE identity; Railnet-linked","Category":"Fraudulent historical registration (withdrawn)","Route Status":"Not currently originating","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"malicious infrastructure registration; Railnet ecosystem","Evidence Summary":"Recorded Future found that AS213511 used the identity of an unrelated Dutch construction company and operated through the Railnet ecosystem; the legitimate VSVK business denied involvement.","Evidence Date":"2025-11-06","FP Risk":"Low","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High for fraudulent historical registration; that is not evidence against the impersonated legitimate company.","Current Status Note":"Not announcing routes on 2026-09-15, though the ASN remains in the current Spamhaus ASN-DROP feed. Do not label the impersonated company malicious.","Source IDs":"S01, S02, X031"},{"ASN":"AS213999","Organization":"THE-CLIENTS WorkTitans B.V.","Aliases":"THE.Hosting clients; Stark Industries-linked","Category":"Current ASN-DROP entry, currently withdrawn","Route Status":"Not currently originating","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"Stark/PQ.Hosting/THE.Hosting infrastructure","Evidence Summary":"The 2026-09-15 Spamhaus ASN-DROP feed associates AS213999 with stark-industries.solutions. This is a current block-oriented source signal, but no independent provider-level campaign attribution was established in this review.","Evidence Date":"2026-09-15","FP Risk":"Low","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High for current feed inclusion; medium for analytical attribution because this row relies on the live feed rather than a detailed public case report.","Current Status Note":"Not announcing routes on 2026-09-15 despite current ASN-DROP inclusion. Treat as a tombstone until route and holder are revalidated.","Source IDs":"S01, S02"},{"ASN":"AS215439","Organization":"PLAY2GO-NET PLAY2GO INTERNATIONAL LIMITED","Aliases":"","Category":"Conditional fast-flux ASN seed","Route Status":"Announced","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"Fast-flux phishing infrastructure","Evidence Summary":"Conditional fast-flux analytic includes this ASN. Source-scoped evidence does not establish that the provider or every tenant is malicious.","Evidence Date":"2026-09-15","FP Risk":"High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"High analytic membership, low ASN-wide attribution","Current Status Note":"Disabled pending independent or local corroboration.","Source IDs":"N38"},{"ASN":"AS394711","Organization":"KORGRID - KorGrid, LLC","Aliases":"LIMENET (historical)","Category":"Historical LIMENET evidence; current KorGrid continuity unresolved","Route Status":"Announced","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"Historical ransomware malvertising and brute-force","Evidence Summary":"Censys described historical LIMENET AS394711 as a known bulletproof-hosting monolith; Rapid7 and time-matched Cisco Talos data add historical abuse context. The current holder is KORGRID / KorGrid LLC. Continuity or reassignment is unresolved, so the BPH label is not carried to the current holder and the row remains disabled.","Evidence Date":"2026-09-15","FP Risk":"Critical","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Historical evidence only; do not transfer reputation to current holder","Current Status Note":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N19, N35, N37"},{"ASN":"AS32167","Organization":"LSHIY-USER-CONTENT - LSHIY LLC","Aliases":"LSHIY-USER-CONTENT; LSHIY LLC; sibling AS955","Category":"Campaign watch","Route Status":"Announced","Default Tier":"T3 Context","Enabled":"Yes","Actors / Campaigns":"LSHIY password spray (Azure CLI / ROPC against Entra ID)","Evidence Summary":"Huntress attributed most of an Entra ID password and token spray, 81 million login attempts and 78 compromised accounts across 64 organizations between 2026-06-12 and 2026-06-26, to 2a0a:d683::/32 originated by AS32167. On 2026-07-02 LSHIY told Huntress the abuser was a bring-your-own-IP customer and suspended it. The operators moved to FranTech AS53667 and then 3xK AS200373, both already catalogued.","Evidence Date":"2026-07-02","FP Risk":"High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Primary source names the ASN or an address it originated during the activity","Current Status Note":"T3 until 2026-12-29.","Source IDs":"X008, N01"},{"ASN":"AS213250","Organization":"ITP-SOLUTIONS Dominic Scholz trading as ITP-Solutions GmbH & Co. KG","Aliases":"","Category":"Campaign watch","Route Status":"Announced","Default Tier":"T3 Context","Enabled":"Yes","Actors / Campaigns":"Storm-3168 compromised service principals","Evidence Summary":"Microsoft published 45.131.66.106 as a Storm-3168 source for App Service probing and malicious Azure Resource Manager requests made with compromised service principals. 45.131.66.0/23 was originated by AS213250 during the activity and still is.","Evidence Date":"2026-09-25","FP Risk":"High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Primary source names the ASN or an address it originated during the activity","Current Status Note":"T3 until 2027-03-24.","Source IDs":"N52, N01"},{"ASN":"AS19318","Organization":"IS-AS-1 - Interserver, Inc","Aliases":"","Category":"Campaign watch","Route Status":"Announced","Default Tier":"T3 Context","Enabled":"Yes","Actors / Campaigns":"Storm-3168 compromised service principals","Evidence Summary":"Microsoft published 64.20.53.230 as a Storm-3168 source for App Service probing. 64.20.32.0/19 was originated by AS19318 during the activity and still is.","Evidence Date":"2026-09-25","FP Risk":"High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Primary source names the ASN or an address it originated during the activity","Current Status Note":"T3 until 2027-03-24.","Source IDs":"N52, N01"},{"ASN":"AS212171","Organization":"Local-as Local NCC Ltd.","Aliases":"","Category":"Campaign watch","Route Status":"Announced","Default Tier":"T3 Context","Enabled":"Yes","Actors / Campaigns":"FortiBleed FortiGate SSL-VPN brute force","Evidence Summary":"The FBI and USSS FortiBleed advisory lists 185.199.199.56 (observed 2026-06-25) among IPs conducting brute force or authenticating with compromised accounts. 185.199.196.0/22 was originated by AS212171 during the activity and is now originated by AS213929.","Evidence Date":"2026-10-06","FP Risk":"High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Primary source names the ASN or an address it originated during the activity","Current Status Note":"T3 until 2027-04-04.","Source IDs":"N62, N01"},{"ASN":"AS213929","Organization":"UP-NETWORK UP-NETWORK Sarl","Aliases":"","Category":"Campaign watch","Route Status":"Announced","Default Tier":"T3 Context","Enabled":"Yes","Actors / Campaigns":"FortiBleed FortiGate SSL-VPN brute force","Evidence Summary":"Current origin of 185.199.196.0/22, which held 185.199.199.56 when the FBI and USSS observed it in FortiBleed brute force on 2026-06-25 under AS212171.","Evidence Date":"2026-10-06","FP Risk":"High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Primary source names the ASN or an address it originated during the activity","Current Status Note":"T3 until 2027-04-04.","Source IDs":"N62, N01"},{"ASN":"AS210328","Organization":"ALMAZ AO ALMAZ","Aliases":"","Category":"Campaign watch","Route Status":"Announced","Default Tier":"T3 Context","Enabled":"Yes","Actors / Campaigns":"FortiBleed FortiGate SSL-VPN brute force","Evidence Summary":"Current origin of 185.136.15.0/24. The FBI and USSS observed 185.136.15.43 and 185.136.15.66 in FortiBleed brute force from 2026-06-27 to 2026-07-23, when the prefix was originated by ASN-DROP listed AS205997, which stopped originating in August.","Evidence Date":"2026-10-06","FP Risk":"High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Primary source names the ASN or an address it originated during the activity","Current Status Note":"T3 until 2027-04-04.","Source IDs":"N62, N01"},{"ASN":"AS201002","Organization":"PebbleHost-Customers PebbleHost Ltd","Aliases":"","Category":"Campaign watch","Route Status":"Announced","Default Tier":"T3 Context","Enabled":"Yes","Actors / Campaigns":"FortiBleed FortiGate SSL-VPN brute force","Evidence Summary":"The FBI and USSS observed 193.8.186.33 in FortiBleed brute force from 2026-06-18 to 2026-07-20. 193.8.186.0/24 was originated by AS201002 then and now.","Evidence Date":"2026-10-06","FP Risk":"High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Primary source names the ASN or an address it originated during the activity","Current Status Note":"T3 until 2027-04-04.","Source IDs":"N62, N01"},{"ASN":"AS267784","Organization":"AS267784 - Flyservers S.A.","Aliases":"","Category":"Campaign watch","Route Status":"Announced","Default Tier":"T3 Context","Enabled":"Yes","Actors / Campaigns":"FortiBleed FortiGate SSL-VPN brute force","Evidence Summary":"The FBI and USSS observed 45.227.254.210 in FortiBleed brute force from 2026-06-18 to 2026-07-23. 45.227.254.0/24 was originated by AS267784 then and now. Sibling of Flyservers AS209588, already T2 High.","Evidence Date":"2026-10-06","FP Risk":"High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Primary source names the ASN or an address it originated during the activity","Current Status Note":"T3 until 2027-04-04.","Source IDs":"N62, N01"},{"ASN":"AS400940","Organization":"RAILWAY - Railway","Aliases":"","Category":"Campaign watch ended; retained for history","Route Status":"Announced","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"EvilTokens device-code phishing and M365 token replay","Evidence Summary":"Huntress tied a device-code phishing and token replay campaign against 344 organizations, 2026-02-19 to mid-March 2026, to Railway PaaS ranges 162.220.232.0/22 and 162.220.234.0/22, with 162.220.234.41 the dominant token engine. Microsoft listed both ranges as threat actor infrastructure observed with sign-in on 2026-04-06.","Evidence Date":"2026-04-06","FP Risk":"Very High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Primary source names the ASN or an address it originated during the activity","Current Status Note":"Campaign watch ended 2026-10-03: 1 campaign (N58, N59), newest report 2026-04-06.","Source IDs":"N58, N59, N01"},{"ASN":"AS61046","Organization":"HZ-UK-AS HZ Hosting Ltd","Aliases":"","Category":"Campaign watch","Route Status":"Announced","Default Tier":"T3 Context","Enabled":"Yes","Actors / Campaigns":"AI-enabled device-code phishing","Evidence Summary":"Microsoft listed 185.81.113.0 (HZ Hosting) as threat actor infrastructure observed with sign-in. 185.81.112.0/23 is originated by AS61046.","Evidence Date":"2026-04-06","FP Risk":"Very High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Primary source names the ASN or an address it originated during the activity","Current Status Note":"Campaign watch: 3 campaigns across the HZ Hosting family (N07, N06, N59).","Source IDs":"N59, N01"},{"ASN":"AS43350","Organization":"NFORCE NForce Entertainment B.V.","Aliases":"","Category":"Campaign watch ended; retained for history","Route Status":"Announced","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"Palo Alto GlobalProtect login brute force","Evidence Summary":"GreyNoise attributed most of over 9 million GlobalProtect login sessions, late September to mid-October 2025, to four ASNs including AS43350.","Evidence Date":"2025-12-04","FP Risk":"Very High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Primary source names the ASN or an address it originated during the activity","Current Status Note":"Campaign watch ended 2026-06-02: 1 campaign (N60), newest report 2025-12-04.","Source IDs":"N60, N01"},{"ASN":"AS215929","Organization":"datacampus Data Campus Limited","Aliases":"","Category":"Campaign watch ended; retained for history","Route Status":"Announced","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"Palo Alto GlobalProtect login brute force","Evidence Summary":"GreyNoise attributed most of over 9 million GlobalProtect login sessions, late September to mid-October 2025, to four ASNs including AS215929.","Evidence Date":"2025-12-04","FP Risk":"Very High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Primary source names the ASN or an address it originated during the activity","Current Status Note":"Campaign watch ended 2026-06-02: 1 campaign (N60), newest report 2025-12-04.","Source IDs":"N60, N01"},{"ASN":"AS211632","Organization":"ORG-ISI14-RIPE Internet Solutions & Innovations LTD.","Aliases":"","Category":"Campaign watch ended; retained for history","Route Status":"Announced","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"Palo Alto GlobalProtect login brute force","Evidence Summary":"GreyNoise attributed most of over 9 million GlobalProtect login sessions, late September to mid-October 2025, to four ASNs including AS211632.","Evidence Date":"2025-12-04","FP Risk":"Very High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Primary source names the ASN or an address it originated during the activity","Current Status Note":"Campaign watch ended 2026-06-02: 1 campaign (N60), newest report 2025-12-04.","Source IDs":"N60, N01"},{"ASN":"AS214238","Organization":"iwihost HOST TELECOM LTD","Aliases":"","Category":"Campaign watch ended; retained for history","Route Status":"Announced","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"Tycoon 2FA AiTM operator logins","Evidence Summary":"eSentire saw post-takedown Tycoon 2FA Microsoft 365 login attempts from AS214238, and ProxyLine use through it in Gmail-targeted campaigns since at least February 2026.","Evidence Date":"2026-04-01","FP Risk":"Very High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Primary source names the ASN or an address it originated during the activity","Current Status Note":"Campaign watch ended 2026-09-28: 1 campaign (N10), newest report 2026-04-01.","Source IDs":"N10, N01"},{"ASN":"AS204957","Organization":"GREENFLOID-AS ROUTE 95 LLC","Aliases":"","Category":"Campaign watch ended; retained for history","Route Status":"Announced","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"Tycoon 2FA AiTM operator logins","Evidence Summary":"eSentire saw post-takedown Tycoon 2FA Microsoft 365 login attempts from AS204957.","Evidence Date":"2026-04-01","FP Risk":"Very High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Primary source names the ASN or an address it originated during the activity","Current Status Note":"Campaign watch ended 2026-09-28: 1 campaign (N10), newest report 2026-04-01.","Source IDs":"N10, N01"},{"ASN":"AS215540","Organization":"GCS-AS GLOBAL CONNECTIVITY SOLUTIONS LLP","Aliases":"","Category":"Campaign watch","Route Status":"Announced","Default Tier":"T3 Context","Enabled":"Yes","Actors / Campaigns":"Tycoon 2FA AiTM operator logins; Akira ransomware targeting SonicWall SSL VPN","Evidence Summary":"eSentire saw pre-takedown Tycoon 2FA Microsoft 365 login attempts from AS215540. 185.168.208.102, an Akira SonicWall VPN client IP published by Arctic Wolf in 2025, is now originated by AS215540.","Evidence Date":"2026-04-01","FP Risk":"Very High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Primary source names the ASN or an address it originated during the activity","Current Status Note":"Campaign watch: 2 campaigns (N06, N10).","Source IDs":"N10, N06, N01"},{"ASN":"AS35758","Organization":"HQSERV_NETWORKS Rachamim Aviel Twito","Aliases":"","Category":"Campaign watch ended; retained for history","Route Status":"Announced","Default Tier":"T4 Review","Enabled":"No","Actors / Campaigns":"Iran-nexus Microsoft 365 password spray","Evidence Summary":"Check Point reported Microsoft 365 password spray waves on 2026-03-03, 03-13 and 03-23 against Israel and the UAE using commercial VPN nodes hosted at AS35758, including Windscribe exits geolocated in Israel.","Evidence Date":"2026-03-31","FP Risk":"Very High","Provider Role Assessment":"Observed infrastructure use. No provider-complicity claim.","Confidence Reason":"Primary source names the ASN or an address it originated during the activity","Current Status Note":"Campaign watch ended 2026-09-27: 1 campaign (N61), newest report 2026-03-31.","Source IDs":"N61, N01"}],"published_iocs":[{"Type":"Application ID","Indicator":"29d9ed98-a469-4536-ade2-f981bc1d605e","Campaign / Provider":"Tycoon 2FA Microsoft Authentication Broker application ID; GhostCode Microsoft Authentication Broker","Observed From":"","Observed To / Report Date":"2026-09-15","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Cloud authentication and API audit logs; Legitimate Microsoft first-party app abused in device-code flow","Default Use":"Alert when the application ID appears with unusual authentication, enrollment, recon, or exfiltration behavior.; Behavioral correlation only; legitimate first-party application, not a malicious-app denylist entry.","Source IDs":"N34, N48","Notes":"Validate tenant-approved applications and expected client/resource use before containment. Source observation scope: Late August 2026."},{"Type":"Application ID","Indicator":"9199bf20-a13f-4107-85dc-02114787ef48","Campaign / Provider":"PREY-0058 anomalous client application ID","Observed From":"","Observed To / Report Date":"2026-09-15","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Cloud authentication and API audit logs","Default Use":"Alert when the application ID appears with unusual authentication, enrollment, recon, or exfiltration behavior.","Source IDs":"N23","Notes":"Validate tenant-approved applications and expected client/resource use before containment."},{"Type":"Application ID","Indicator":"c999ed3e-27ae-4cb3-b3a2-46b056af63d3","Campaign / Provider":"PREY-0058 anomalous resource application ID","Observed From":"","Observed To / Report Date":"2026-09-15","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Cloud authentication and API audit logs","Default Use":"Alert when the application ID appears with unusual authentication, enrollment, recon, or exfiltration behavior.","Source IDs":"N23","Notes":"Validate tenant-approved applications and expected client/resource use before containment."},{"Type":"CIDR","Indicator":"103.113.68.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"103.113.68.0/24","Current ASN":"AS33993","Current Prefix":"103.113.68.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"109.104.156.0/24","Campaign / Provider":"MuddyWater / BugSleep infrastructure cluster","Observed From":"2026-01-28","Observed To / Report Date":"2026-01-28","Reported / Historical ASN":"AS203020","Reported / Historical Prefix":"109.104.156.0/24","Current ASN":"AS203020","Current Prefix":"109.104.156.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Actor-attributed infrastructure prediction; not sign-in-source evidence","Default Use":"Time-bounded network hunt and enrichment. Require local behavioral corroboration before blocking.","Source IDs":"N08","Notes":"Augur labels recent infrastructure across AS62005, AS62240, and AS203020 and assesses provider diversification."},{"Type":"CIDR","Indicator":"13.52.201.0/24","Campaign / Provider":"UNK_CondorFiltration / TeamFiltration","Observed From":"","Observed To / Report Date":"2026-09-22","Reported / Historical ASN":"AS16509","Reported / Historical Prefix":"13.52.201.0/24","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked","Telemetry Context":"AWS EC2 password-spray range","Default Use":"Correlate dormant-account spraying, stale TeamFiltration user agent, failed-to-success activity, and rapid ASN change; do not block AWS or DataCamp wholesale.","Source IDs":"N57","Notes":"Proofpoint reported 1,487 EC2 spray sources and a separate post-access VPN node. Shared hosting attribution is context only."},{"Type":"CIDR","Indicator":"146.19.49.0/25","Campaign / Provider":"MuddyWater / BugSleep infrastructure cluster","Observed From":"2025-09-18","Observed To / Report Date":"2025-09-18","Reported / Historical ASN":"AS62005","Reported / Historical Prefix":"146.19.49.0/25","Current ASN":"AS62005","Current Prefix":"146.19.49.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Actor-attributed infrastructure prediction; not sign-in-source evidence","Default Use":"Time-bounded network hunt and enrichment. Require local behavioral corroboration before blocking.","Source IDs":"N08","Notes":"Augur labels recent infrastructure across AS62005, AS62240, and AS203020 and assesses provider diversification."},{"Type":"CIDR","Indicator":"171.22.119.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"171.22.119.0/24","Current ASN":"AS203273","Current Prefix":"171.22.119.0/24","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"18.144.76.0/24","Campaign / Provider":"UNK_CondorFiltration / TeamFiltration","Observed From":"","Observed To / Report Date":"2026-09-22","Reported / Historical ASN":"AS16509","Reported / Historical Prefix":"18.144.76.0/24","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked","Telemetry Context":"AWS EC2 password-spray range","Default Use":"Correlate dormant-account spraying, stale TeamFiltration user agent, failed-to-success activity, and rapid ASN change; do not block AWS or DataCamp wholesale.","Source IDs":"N57","Notes":"Proofpoint reported 1,487 EC2 spray sources and a separate post-access VPN node. Shared hosting attribution is context only."},{"Type":"CIDR","Indicator":"185.170.144.0/24","Campaign / Provider":"Zservers / XHOST","Observed From":"","Observed To / Report Date":"2025-03-11","Reported / Historical ASN":"AS197414","Reported / Historical Prefix":"185.170.144.0/24","Current ASN":"AS50053","Current Prefix":"185.170.144.0/24","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S15, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"185.234.59.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"185.234.59.0/24","Current ASN":"AS33993","Current Prefix":"185.234.59.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"185.235.242.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"185.235.242.0/24","Current ASN":"AS33993","Current Prefix":"185.235.242.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"185.250.149.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"185.250.149.0/24","Current ASN":"AS33993","Current Prefix":"185.250.149.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"188.119.122.0/24","Campaign / Provider":"MuddyWater / BugSleep infrastructure cluster","Observed From":"2025-09-20","Observed To / Report Date":"2025-09-20","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"188.119.122.0/24","Current ASN":"AS62240","Current Prefix":"188.119.122.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Actor-attributed infrastructure prediction; not sign-in-source evidence","Default Use":"Time-bounded network hunt and enrichment. Require local behavioral corroboration before blocking.","Source IDs":"N08","Notes":"Augur labels recent infrastructure across AS62005, AS62240, and AS203020 and assesses provider diversification."},{"Type":"CIDR","Indicator":"193.201.126.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"193.201.126.0/24","Current ASN":"AS44559","Current Prefix":"193.201.126.0/24","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"2.56.178.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"2.56.178.0/24","Current ASN":"AS33993","Current Prefix":"2.56.178.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"2.59.218.0/24","Campaign / Provider":"MuddyWater / BugSleep infrastructure cluster","Observed From":"2025-09-18","Observed To / Report Date":"2025-09-18","Reported / Historical ASN":"AS62005","Reported / Historical Prefix":"2.59.218.0/24","Current ASN":"AS62005","Current Prefix":"2.59.218.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Actor-attributed infrastructure prediction; not sign-in-source evidence","Default Use":"Time-bounded network hunt and enrichment. Require local behavioral corroboration before blocking.","Source IDs":"N08","Notes":"Augur labels recent infrastructure across AS62005, AS62240, and AS203020 and assesses provider diversification."},{"Type":"CIDR","Indicator":"213.232.236.0/25","Campaign / Provider":"MuddyWater / BugSleep infrastructure cluster","Observed From":"2025-09-19","Observed To / Report Date":"2025-09-19","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"213.232.236.0/25","Current ASN":"AS62240","Current Prefix":"213.232.236.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Actor-attributed infrastructure prediction; not sign-in-source evidence","Default Use":"Time-bounded network hunt and enrichment. Require local behavioral corroboration before blocking.","Source IDs":"N08","Notes":"Augur labels recent infrastructure across AS62005, AS62240, and AS203020 and assesses provider diversification."},{"Type":"CIDR","Indicator":"213.232.236.128/25","Campaign / Provider":"MuddyWater / BugSleep infrastructure cluster","Observed From":"2025-09-19","Observed To / Report Date":"2025-09-19","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"213.232.236.128/25","Current ASN":"AS62240","Current Prefix":"213.232.236.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Actor-attributed infrastructure prediction; not sign-in-source evidence","Default Use":"Time-bounded network hunt and enrichment. Require local behavioral corroboration before blocking.","Source IDs":"N08","Notes":"Augur labels recent infrastructure across AS62005, AS62240, and AS203020 and assesses provider diversification."},{"Type":"CIDR","Indicator":"3.101.0.0/16","Campaign / Provider":"UNK_CondorFiltration / TeamFiltration","Observed From":"","Observed To / Report Date":"2026-09-22","Reported / Historical ASN":"AS16509","Reported / Historical Prefix":"3.101.0.0/16","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked","Telemetry Context":"AWS EC2 password-spray range","Default Use":"Correlate dormant-account spraying, stale TeamFiltration user agent, failed-to-success activity, and rapid ASN change; do not block AWS or DataCamp wholesale.","Source IDs":"N57","Notes":"Proofpoint reported 1,487 EC2 spray sources and a separate post-access VPN node. Shared hosting attribution is context only."},{"Type":"CIDR","Indicator":"45.12.114.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"45.12.114.0/24","Current ASN":"AS33993","Current Prefix":"45.12.114.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"45.12.115.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"45.12.115.0/24","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"45.128.49.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"45.128.49.0/24","Current ASN":"AS33993","Current Prefix":"45.128.49.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"45.128.53.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"45.128.53.0/24","Current ASN":"AS33993","Current Prefix":"45.128.53.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"45.138.157.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"45.138.157.0/24","Current ASN":"AS48347","Current Prefix":"45.138.157.0/24","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"45.144.30.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"45.144.30.0/24","Current ASN":"AS33993","Current Prefix":"45.144.30.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"45.144.31.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"45.144.31.0/24","Current ASN":"AS33993","Current Prefix":"45.144.31.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"45.150.64.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"45.150.64.0/24","Current ASN":"AS33993","Current Prefix":"45.150.64.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"45.153.231.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"45.153.231.0/24","Current ASN":"AS62240","Current Prefix":"45.153.231.0/24","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"45.67.230.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"45.67.230.0/24","Current ASN":"AS33993","Current Prefix":"45.67.230.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"45.84.1.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"45.84.1.0/24","Current ASN":"AS33993","Current Prefix":"45.84.1.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"62.204.35.0/25","Campaign / Provider":"MuddyWater / BugSleep infrastructure cluster","Observed From":"2025-09-18","Observed To / Report Date":"2025-09-18","Reported / Historical ASN":"AS62005","Reported / Historical Prefix":"62.204.35.0/25","Current ASN":"AS62005","Current Prefix":"62.204.35.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Actor-attributed infrastructure prediction; not sign-in-source evidence","Default Use":"Time-bounded network hunt and enrichment. Require local behavioral corroboration before blocking.","Source IDs":"N08","Notes":"Augur labels recent infrastructure across AS62005, AS62240, and AS203020 and assesses provider diversification."},{"Type":"CIDR","Indicator":"62.204.35.128/25","Campaign / Provider":"MuddyWater / BugSleep infrastructure cluster","Observed From":"2025-09-18","Observed To / Report Date":"2025-09-18","Reported / Historical ASN":"AS62005","Reported / Historical Prefix":"62.204.35.128/25","Current ASN":"AS62005","Current Prefix":"62.204.35.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Actor-attributed infrastructure prediction; not sign-in-source evidence","Default Use":"Time-bounded network hunt and enrichment. Require local behavioral corroboration before blocking.","Source IDs":"N08","Notes":"Augur labels recent infrastructure across AS62005, AS62240, and AS203020 and assesses provider diversification."},{"Type":"CIDR","Indicator":"87.251.64.0/24","Campaign / Provider":"Zservers / XHOST","Observed From":"","Observed To / Report Date":"2025-03-11","Reported / Historical ASN":"AS197414","Reported / Historical Prefix":"87.251.64.0/24","Current ASN":"AS212835","Current Prefix":"87.251.64.0/24","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S15, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"91.207.183.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"91.207.183.0/24","Current ASN":"AS33993","Current Prefix":"91.207.183.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"94.131.113.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"94.131.113.0/24","Current ASN":"AS33993","Current Prefix":"94.131.113.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"CIDR","Indicator":"94.131.121.0/24","Campaign / Provider":"Stark Industries / PQ.Hosting / UFO Hosting","Observed From":"","Observed To / Report Date":"2025-08-27","Reported / Historical ASN":"AS33993","Reported / Historical Prefix":"94.131.121.0/24","Current ASN":"AS33993","Current Prefix":"94.131.121.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published hosting/infrastructure range","Default Use":"Revalidate before current blocking; use ASN catalog tier for identity monitoring.","Source IDs":"S12, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"Device ID","Indicator":"4e537622-2514-48b8-84ed-0139549cfab0","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Attacker-enrolled device record","Default Use":"Incident-specific retro-hunt only; does not identify other tenants.","Source IDs":"N48","Notes":"Source observation scope: Late August2026 incident."},{"Type":"Device ID","Indicator":"5e83a216-f67e-43b8-a129-f67666a001dd","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Attacker-enrolled device record","Default Use":"Incident-specific retro-hunt only; does not identify other tenants.","Source IDs":"N48","Notes":"Source observation scope: Late August2026 incident."},{"Type":"Device ID","Indicator":"6c290bcc-62d3-40bd-a774-816109af6729","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Attacker-enrolled device record","Default Use":"Incident-specific retro-hunt only; does not identify other tenants.","Source IDs":"N48","Notes":"Source observation scope: Late August2026 incident."},{"Type":"Domain","Indicator":"*.981666.xyz","Campaign / Provider":"Kapibala","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"C2","Default Use":"Exact-indicator hunt with campaign and observation-date context; revalidate routing and ownership before blocking.","Source IDs":"N39","Notes":"High, Corroborate DNS and endpoint telemetry"},{"Type":"Domain","Indicator":"1jabber.com","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"2026-05-21","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Service infrastructure","Default Use":"Historical DNS/proxy/authentication retro-hunt; verify current ownership and resolution.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"Domain","Indicator":"1vpns.com","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"2026-05-21","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Service infrastructure","Default Use":"Historical DNS/proxy/authentication retro-hunt; verify current ownership and resolution.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"Domain","Indicator":"1vpns.net","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"2026-05-21","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Service infrastructure","Default Use":"Historical DNS/proxy/authentication retro-hunt; verify current ownership and resolution.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"Domain","Indicator":"1vpns.org","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"2026-05-21","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Service infrastructure","Default Use":"Historical DNS/proxy/authentication retro-hunt; verify current ownership and resolution.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"Domain","Indicator":"360apartmentrenovation.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"abswaranty.net","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"account-access-rc3uenqi.elitechiropracticandrehab.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"account-access-thlwvhxo.cxxzf.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"account-access-unlcjkmj.androidpreneur.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"aceshopequlpment.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"add-passkey.com","Campaign / Provider":"Passkey-themed social engineering and cloud compromise","Observed From":"","Observed To / Report Date":"2026-09-09","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N27","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain","Indicator":"alllitematerial.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"ankerrpak.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"asllancorporation.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"authenticate-access-unb5gtsf.xhscyp.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"bjssourcing.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Observed business impersonation sender domain","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N48","Notes":"Source observation scope: Registered 2026-08-17; campaign late August."},{"Type":"Domain","Indicator":"bochacornpany.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"bpdaersa.click","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-03-01","Observed To / Report Date":"2026-03-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published malware delivery domain","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026-03."},{"Type":"Domain","Indicator":"byveo.org","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-07-01","Observed To / Report Date":"2026-07-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published malware delivery domain","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026-07."},{"Type":"Domain","Indicator":"canada-post11.com","Campaign / Provider":"Fast-flux phishing","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Canada Post lure","Default Use":"Exact-indicator hunt with campaign and observation-date context; revalidate routing and ownership before blocking.","Source IDs":"N38","Notes":"High source-reported, Historical report IOC; refresh current DNS before enforcement"},{"Type":"Domain","Indicator":"carkeysexpres.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"chartered.flipbookonlinevault.com","Campaign / Provider":"GhostCode","Observed From":"2026-08-01","Observed To / Report Date":"2026-08-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Observed relay host","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N48","Notes":"Source observation scope: Late August 2026."},{"Type":"Domain","Indicator":"chayahconsulting-group.net","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"clear90489058903-document.workers.dev","Campaign / Provider":"ARToken / EvilTokens Microsoft 365 phishing","Observed From":"","Observed To / Report Date":"2026-07-01","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N20","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain","Indicator":"craecominc.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"crvsurveilance.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"curtiinco.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"cyrna.top","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-08-01","Observed To / Report Date":"2026-08-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published malware delivery domain","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026-08."},{"Type":"Domain","Indicator":"dashboard-bl.pamconj.com","Campaign / Provider":"ARToken / EvilTokens Microsoft 365 phishing","Observed From":"","Observed To / Report Date":"2026-07-01","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N20","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain","Indicator":"dernaeng.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"divekickspolic.org","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published malware delivery domain","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026; month unspecified."},{"Type":"Domain","Indicator":"douglasdynarnics.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"drasw.club","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-08-01","Observed To / Report Date":"2026-08-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published malware delivery domain","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026-08."},{"Type":"Domain","Indicator":"etia.ca","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-01-01","Observed To / Report Date":"2026-01-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published malware delivery domain","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026-01."},{"Type":"Domain","Indicator":"etranferts.com","Campaign / Provider":"Fast-flux phishing","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Interac impersonation","Default Use":"Exact-indicator hunt with campaign and observation-date context; revalidate routing and ownership before blocking.","Source IDs":"N38","Notes":"High source-reported, Historical report IOC; refresh current DNS before enforcement"},{"Type":"Domain","Indicator":"evollvtechnology.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"flipbookonlinevault.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Relay / decoy PDF host","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"flipbookviewer.us","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Relay / decoy PDF host","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"frugeseafoods.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"gliderrompercycl.com","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published malware delivery domain","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026; month unspecified."},{"Type":"Domain","Indicator":"greenlightdlstribution.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"groy.cc","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-02-01","Observed To / Report Date":"2026-02-28","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published malware delivery domain","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026-02."},{"Type":"Domain","Indicator":"guach.net","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-06-01","Observed To / Report Date":"2026-06-30","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published malware delivery domain","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026-06."},{"Type":"Domain","Indicator":"houchems.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"identity-access-1w2m8s2x.arlingtonhousecleaning.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"inflnity-tx.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"ingredlon.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"integratedsso.com","Campaign / Provider":"Passkey-themed social engineering and cloud compromise","Observed From":"","Observed To / Report Date":"2026-09-09","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N27","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain","Indicator":"itechx.tel","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-04-01","Observed To / Report Date":"2026-04-30","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published malware delivery domain","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026-04."},{"Type":"Domain","Indicator":"janlssary.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"keysyncos.com","Campaign / Provider":"Passkey-themed social engineering and cloud compromise","Observed From":"","Observed To / Report Date":"2026-09-09","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N27","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain","Indicator":"kinaaxis.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"kwservlces.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"laseroilfleld.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"matjk.click","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-03-01","Observed To / Report Date":"2026-03-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published malware delivery domain","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026-03."},{"Type":"Domain","Indicator":"mfa-access-pyvxbnjc.atomzilla.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"muvb.net","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-02-01","Observed To / Report Date":"2026-02-28","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published malware delivery domain","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026-02."},{"Type":"Domain","Indicator":"myconnectkey.com","Campaign / Provider":"Passkey-themed social engineering and cloud compromise","Observed From":"","Observed To / Report Date":"2026-09-09","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N27","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain","Indicator":"njjutb.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"nyrnetroglass.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"oktasession.com","Campaign / Provider":"Passkey-themed social engineering and cloud compromise","Observed From":"","Observed To / Report Date":"2026-09-09","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N27","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain","Indicator":"onestep-access-aosbgdan.tv-appspot.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"orchadmedicalmgt.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"oskeyregister.com","Campaign / Provider":"Passkey-themed social engineering and cloud compromise","Observed From":"","Observed To / Report Date":"2026-09-09","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N27","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain","Indicator":"oskeysync.com","Campaign / Provider":"Passkey-themed social engineering and cloud compromise","Observed From":"","Observed To / Report Date":"2026-09-09","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N27","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain","Indicator":"pamconj.com","Campaign / Provider":"ARToken / EvilTokens Microsoft 365 phishing","Observed From":"","Observed To / Report Date":"2026-07-01","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N20","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain","Indicator":"pantera-energy.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"passkeyhelpdesk.com","Campaign / Provider":"Passkey-themed social engineering and cloud compromise","Observed From":"","Observed To / Report Date":"2026-09-09","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N27","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain","Indicator":"patriothealthpartner.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"performanceservlces.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"pirctobln.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"plescla-cd.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"portalsetuphub.com","Campaign / Provider":"Passkey-themed social engineering and cloud compromise","Observed From":"","Observed To / Report Date":"2026-09-09","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N27","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain","Indicator":"ptpttx.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"qumel.link","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-07-01","Observed To / Report Date":"2026-07-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published malware delivery domain","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026-07."},{"Type":"Domain","Indicator":"rapidlntermodal.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"reynoldsjace5.workers.dev","Campaign / Provider":"ARToken / EvilTokens Microsoft 365 phishing","Observed From":"","Observed To / Report Date":"2026-07-01","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N20","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain","Indicator":"rpgsurfacepreps.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"ruten.observer","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published malware delivery domain","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026-06/07."},{"Type":"Domain","Indicator":"salisburymore.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"saml-access-0yni8zkk.deltarstar.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"saml-access-4ejlnged.cciwedding.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"saml-access-bgzdiwai.pelicol.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"saml-access-ebntirhn.followmyitems.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"saml-access-fgphrx1b.geefjelevenkleur.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"saml-access-hjg5zb1m.schuelerhvac.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"saml-access-qhtexulk.atomzilla.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"saml-access-umjn1zxd.vnamecard.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"saml-access-vdjnpebo.alltoyotatrucksuvparts.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"saml-access-whwhikxl.lygdhc.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"secure-access-ht0ysxlq.alltoyotatrucksuvparts.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"secure-dns-hub.com","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published malware delivery domain","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026-07 to current as of Sept29."},{"Type":"Domain","Indicator":"session-access-hrh9axw6.androidpreneur.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"setupmypasskey.com","Campaign / Provider":"Passkey-themed social engineering and cloud compromise","Observed From":"","Observed To / Report Date":"2026-09-09","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N27","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain","Indicator":"signin-access-3qbuumoo.alltoyotatrucksuvparts.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"signin-access-bpbippyw.geefjelevenkleur.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"signin-access-ltcpr2s7.breakingpandora.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"signin-access-whtc5iq4.accudiodesign.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"spx.pamconj.com","Campaign / Provider":"ARToken / EvilTokens Microsoft 365 phishing","Observed From":"","Observed To / Report Date":"2026-07-01","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N20","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain","Indicator":"stuseamandesilt.org","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published malware delivery domain","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026; month unspecified."},{"Type":"Domain","Indicator":"syncmykey.com","Campaign / Provider":"Passkey-themed social engineering and cloud compromise","Observed From":"","Observed To / Report Date":"2026-09-09","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N27","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain","Indicator":"tealc0n.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"thlnk-arc.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain","Indicator":"validate-access-kgcdauwc.xhscyp.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"validationsetupac.com","Campaign / Provider":"Passkey-themed social engineering and cloud compromise","Observed From":"","Observed To / Report Date":"2026-09-09","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N27","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain","Indicator":"verify-access-6dlrv01r.adogabroad.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"verify-access-umjlvvrx.alltoyotatrucksuvparts.com","Campaign / Provider":"GhostCode","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Published main-kit subdomain; vendor labels compromised site","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Vendor list linked Sept15; specific last-seen not given."},{"Type":"Domain","Indicator":"versaterrm.com","Campaign / Provider":"GhostCode possible association","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Lookalike domain; source association tentative","Default Use":"Investigate/retro-hunt; do not treat as confirmed malicious solely from shared registration attributes.","Source IDs":"N49","Notes":"Source observation scope: August 2026 registrations; last-seen not given. Confidence: Possible association only."},{"Type":"Domain pattern","Indicator":"*.assignpasskey.com","Campaign / Provider":"PREY-0058 cloud data theft and extortion","Observed From":"","Observed To / Report Date":"2026-09-03","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N23","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain pattern","Indicator":"*.mfaregister.com","Campaign / Provider":"PREY-0058 cloud data theft and extortion","Observed From":"","Observed To / Report Date":"2026-09-03","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N23","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain pattern","Indicator":"*.oskey.com","Campaign / Provider":"PREY-0058 cloud data theft and extortion","Observed From":"","Observed To / Report Date":"2026-09-03","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N23","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain pattern","Indicator":"*.oskeyconnect.com","Campaign / Provider":"PREY-0058 cloud data theft and extortion","Observed From":"","Observed To / Report Date":"2026-09-03","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N23","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain pattern","Indicator":"*.oskeysetup.com","Campaign / Provider":"PREY-0058 cloud data theft and extortion","Observed From":"","Observed To / Report Date":"2026-09-03","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N23","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain pattern","Indicator":"*.passkey-mfa.com","Campaign / Provider":"PREY-0058 cloud data theft and extortion","Observed From":"","Observed To / Report Date":"2026-09-03","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N23","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain pattern","Indicator":"*.registermymfa.com","Campaign / Provider":"PREY-0058 cloud data theft and extortion","Observed From":"","Observed To / Report Date":"2026-09-03","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N23","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain pattern","Indicator":"*.secure-passkey.com","Campaign / Provider":"PREY-0058 cloud data theft and extortion","Observed From":"","Observed To / Report Date":"2026-09-03","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N23","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"Domain pattern","Indicator":"*.setpasskey.com","Campaign / Provider":"PREY-0058 cloud data theft and extortion","Observed From":"","Observed To / Report Date":"2026-09-03","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Phishing, identity compromise, or operator infrastructure","Default Use":"Time-bound DNS, proxy, email, and browser hunt; revalidate before blocking.","Source IDs":"N23","Notes":"Domain infrastructure rotates. Correlate with authentication, device enrollment, and session behavior."},{"Type":"File path","Indicator":"/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver","Campaign / Provider":"Citrix CVE-2026-88771 exploitation","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Webshell","Default Use":"Exact-indicator hunt with campaign and observation-date context; revalidate routing and ownership before blocking.","Source IDs":"N40","Notes":"High"},{"Type":"GPO GUID","Indicator":"{22099AD2-E062-4F56-B574-5099BBA4E7A6}","Campaign / Provider":"PAYLOAD ransomware","Observed From":"2026-04-11","Observed To / Report Date":"2026-04-16","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"win Firewall Off GPO","Default Use":"Exact-indicator hunt plus behavior; filenames/GPO names alone are weak indicators.","Source IDs":"N54","Notes":"Source observation scope: 2026-04-13."},{"Type":"GPO GUID","Indicator":"{C897F2C7-C2AC-4E6F-BF48-58036FF29E79}","Campaign / Provider":"PAYLOAD ransomware","Observed From":"2026-04-11","Observed To / Report Date":"2026-04-16","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"PAYLOAD GPO","Default Use":"Exact-indicator hunt plus behavior; filenames/GPO names alone are weak indicators.","Source IDs":"N54","Notes":"Source observation scope: 2026-04-13."},{"Type":"Host name","Indicator":"WIN-LIVFRVQFMKO","Campaign / Provider":"Settra","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Repeated malicious workstation","Default Use":"Exact-indicator hunt with campaign and observation-date context; revalidate routing and ownership before blocking.","Source IDs":"N41","Notes":"High, Correlate with exact C2 and attack behavior; generic machine identifiers can be copied"},{"Type":"IPv4","Indicator":"103.151.103.243","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"103.151.103.0/24","Current ASN":"AS62240","Current Prefix":"103.151.103.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Address Management Inc.; clouvider.co.uk. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"103.152.17.248","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"103.152.17.0/24","Current ASN":"AS62240","Current Prefix":"103.152.17.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"LIR LLC; lir.am. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"103.16.26.135","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"103.16.26.229","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"103.16.27.96","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"103.160.59.97","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-07-01","Observed To / Report Date":"2026-07-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS63023","Current Prefix":"103.160.59.0/24","Current Country":"","Mapping Changed":"Current mapping added","Telemetry Context":"CosmicPulse downloader DLL host","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N55","Notes":"Source observation scope: 2026-07."},{"Type":"IPv4","Indicator":"103.245.231.248","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-01-01","Observed To / Report Date":"2026-01-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS212477","Current Prefix":"103.245.231.0/24","Current Country":"","Mapping Changed":"Current mapping added","Telemetry Context":"CosmicPulse downloader DLL host","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N55","Notes":"Source observation scope: 2026-01."},{"Type":"IPv4","Indicator":"103.245.231.79","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-03-01","Observed To / Report Date":"2026-03-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS212477","Current Prefix":"103.245.231.0/24","Current Country":"","Mapping Changed":"Current mapping added","Telemetry Context":"CosmicPulse downloader DLL host","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N55","Notes":"Source observation scope: 2026-03."},{"Type":"IPv4","Indicator":"104.164.55.46","Campaign / Provider":"PAYLOAD ransomware","Observed From":"2026-04-11","Observed To / Report Date":"2026-04-16","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Listed IOC; individual IP role not specified","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N54","Notes":"Source observation scope: April 2026 incident; source published Sept21."},{"Type":"IPv4","Indicator":"104.194.11.34","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS23470","Reported / Historical Prefix":"","Current ASN":"AS23470","Current Prefix":"104.194.11.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"104.194.8.58","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS23470","Reported / Historical Prefix":"","Current ASN":"AS23470","Current Prefix":"104.194.8.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"104.225.153.141","Campaign / Provider":"Kapibala","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS25820","Current Prefix":"","Current Country":"","Mapping Changed":"Current mapping added","Telemetry Context":"C2","Default Use":"Exact-indicator hunt with campaign and observation-date context; revalidate routing and ownership before blocking.","Source IDs":"N39","Notes":"High, Shared hosting; no provider complicity established"},{"Type":"IPv4","Indicator":"104.238.189.186","Campaign / Provider":"Gamaredon / Primitive Bear C2 or downloader infrastructure","Observed From":"","Observed To / Report Date":"2022-02-03","Reported / Historical ASN":"AS20473","Reported / Historical Prefix":"","Current ASN":"AS20473","Current Prefix":"104.238.188.0/22","Current Country":"","Mapping Changed":"No","Telemetry Context":"Malware C2/downloader infrastructure, not sign-in source","Default Use":"Historical exact-IP hunt; ASN only as contextual risk.","Source IDs":"S08, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"IPv4","Indicator":"104.238.205.105","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS23470","Reported / Historical Prefix":"","Current ASN":"AS23470","Current Prefix":"104.238.205.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"104.28.162.228","Campaign / Provider":"PAYLOAD ransomware","Observed From":"2026-04-11","Observed To / Report Date":"2026-04-16","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Listed IOC; individual IP role not specified","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N54","Notes":"Source observation scope: April 2026 incident; source published Sept21."},{"Type":"IPv4","Indicator":"104.28.163.162","Campaign / Provider":"PAYLOAD ransomware","Observed From":"2026-04-11","Observed To / Report Date":"2026-04-16","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Listed IOC; individual IP role not specified","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N54","Notes":"Source observation scope: April 2026 incident; source published Sept21."},{"Type":"IPv4","Indicator":"107.128.45.122","Campaign / Provider":"UNC6671 multi-brand vishing, AiTM, and SaaS extortion","Observed From":"2026-04-01","Observed To / Report Date":"2026-08-06","Reported / Historical ASN":"AS7018","Reported / Historical Prefix":"","Current ASN":"AS7018","Current Prefix":"107.128.0.0/12","Current Country":"","Mapping Changed":"No","Telemetry Context":"M365 / Okta residential proxy","Default Use":"Short-TTL exact-IP hunt only; do not block the residential ASN.","Source IDs":"N17","Notes":"GTIG warns that most source IPs are commercial VPN nodes and cycle quickly; prioritize TTP and session behavior."},{"Type":"IPv4","Indicator":"107.155.93.154","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS29802","Reported / Historical Prefix":"","Current ASN":"AS29802","Current Prefix":"107.155.93.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"107.158.128.106","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS62904","Reported / Historical Prefix":"","Current ASN":"AS62904","Current Prefix":"107.158.128.0/23","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"107.175.102.58","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS131199","Reported / Historical Prefix":"","Current ASN":"AS131199","Current Prefix":"107.175.102.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"108.59.1.133","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"109.69.58.213","Campaign / Provider":"Reverse-connection endpoint exposed with C2 and persistence tooling","Observed From":"2026-02-03","Observed To / Report Date":"2026-02-03","Reported / Historical ASN":"AS205090","Reported / Historical Prefix":"","Current ASN":"AS200740","Current Prefix":"109.69.58.0/23","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Published campaign infrastructure; ASN attribution is context, not provider attribution","Default Use":"Time-bounded exact-IP alert plus ASN context; revalidate current routing before enforcement.","Source IDs":"N19","Notes":"Keep exact infrastructure evidence separate from any claim of provider complicity."},{"Type":"IPv4","Indicator":"109.94.218.192","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"109.94.218.0/24","Current ASN":"AS62240","Current Prefix":"109.94.218.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Mastercom LLC; mastercommunications.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"111.90.141.47","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"111.90.158.72","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"134.255.210.160","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"134.255.210.26","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"137.184.65.71","Campaign / Provider":"Console Chaos FortiGate management-interface exploitation","Observed From":"2024-11-16","Observed To / Report Date":"2025-01-10","Reported / Historical ASN":"AS14061","Reported / Historical Prefix":"","Current ASN":"AS14061","Current Prefix":"137.184.64.0/20","Current Country":"","Mapping Changed":"No","Telemetry Context":"SSL VPN client","Default Use":"Historical exact-IP hunt; prioritize exposed-management and SSL VPN telemetry over static blocking.","Source IDs":"N09","Notes":"Arctic Wolf observed VPS-origin HTTPS management activity, account creation, SSL VPN changes, and later DCSync."},{"Type":"IPv4","Indicator":"139.99.122.162","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"139.99.149.85","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"139.99.255.144","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"139.99.68.157","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"144.168.41.74","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS29802","Reported / Historical Prefix":"","Current ASN":"AS29802","Current Prefix":"144.168.41.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"144.172.110.103","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS14956","Reported / Historical Prefix":"","Current ASN":"AS14956","Current Prefix":"144.172.110.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"144.172.110.37","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS14956","Reported / Historical Prefix":"","Current ASN":"AS14956","Current Prefix":"144.172.110.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"144.172.110.49","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS14956","Reported / Historical Prefix":"","Current ASN":"AS14956","Current Prefix":"144.172.110.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"145.239.5.30","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"146.70.117.239","Campaign / Provider":"PAYLOAD ransomware","Observed From":"2026-04-11","Observed To / Report Date":"2026-04-16","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Listed IOC; individual IP role not specified","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N54","Notes":"Source observation scope: April 2026 incident; source published Sept21."},{"Type":"IPv4","Indicator":"147.135.11.223","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"147.135.11.234","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"147.135.36.162","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"147.135.40.102","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"147.135.87.184","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"149.102.229.154","Campaign / Provider":"PAYLOAD ransomware","Observed From":"2026-04-11","Observed To / Report Date":"2026-04-16","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Listed IOC; individual IP role not specified","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N54","Notes":"Source observation scope: April 2026 incident; source published Sept21."},{"Type":"IPv4","Indicator":"149.104.78.141","Campaign / Provider":"Citrix CVE-2026-88771 exploitation","Observed From":"2026-09-24","Observed To / Report Date":"2026-09-24","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS154177","Current Prefix":"","Current Country":"","Mapping Changed":"Current mapping added","Telemetry Context":"Exploitation","Default Use":"Exact-indicator hunt with campaign and observation-date context; revalidate routing and ownership before blocking.","Source IDs":"N40","Notes":"High, Stale search indexes also show AS138915; current origin is AS154177. Do not replace verified live mapping with old search result."},{"Type":"IPv4","Indicator":"149.50.127.228","Campaign / Provider":"Doko's Panel / ShinyHunters phishing-panel infrastructure","Observed From":"2026-08-05","Observed To / Report Date":"2026-08-05","Reported / Historical ASN":"AS201814","Reported / Historical Prefix":"","Current ASN":"AS201814","Current Prefix":"149.50.120.0/21","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published campaign infrastructure; ASN attribution is context, not provider attribution","Default Use":"Time-bounded exact-IP alert plus ASN context; revalidate current routing before enforcement.","Source IDs":"N18","Notes":"Keep exact infrastructure evidence separate from any claim of provider complicity."},{"Type":"IPv4","Indicator":"149.50.97.144","Campaign / Provider":"UNC6671 phishing infrastructure","Observed From":"2026-08-06","Observed To / Report Date":"2026-08-06","Reported / Historical ASN":"AS201814","Reported / Historical Prefix":"","Current ASN":"AS201814","Current Prefix":"149.50.96.0/21","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published campaign infrastructure; ASN attribution is context, not provider attribution","Default Use":"Time-bounded exact-IP alert plus ASN context; revalidate current routing before enforcement.","Source IDs":"N17","Notes":"Keep exact infrastructure evidence separate from any claim of provider complicity."},{"Type":"IPv4","Indicator":"149.50.97.174","Campaign / Provider":"Doko's Panel / ShinyHunters phishing-panel infrastructure","Observed From":"2026-08-05","Observed To / Report Date":"2026-08-05","Reported / Historical ASN":"AS201814","Reported / Historical Prefix":"","Current ASN":"AS201814","Current Prefix":"149.50.96.0/21","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published campaign infrastructure; ASN attribution is context, not provider attribution","Default Use":"Time-bounded exact-IP alert plus ASN context; revalidate current routing before enforcement.","Source IDs":"N18","Notes":"Keep exact infrastructure evidence separate from any claim of provider complicity."},{"Type":"IPv4","Indicator":"149.88.104.19","Campaign / Provider":"UNK_CondorFiltration / TeamFiltration","Observed From":"","Observed To / Report Date":"2026-09-22","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS212238","Current Prefix":"149.88.104.0/24","Current Country":"","Mapping Changed":"Not checked","Telemetry Context":"Post-access VPN pivot","Default Use":"Correlate dormant-account spraying, stale TeamFiltration user agent, failed-to-success activity, and rapid ASN change; do not block AWS or DataCamp wholesale.","Source IDs":"N57","Notes":"Proofpoint reported 1,487 EC2 spray sources and a separate post-access VPN node. Shared hosting attribution is context only."},{"Type":"IPv4","Indicator":"151.225.227.193","Campaign / Provider":"GhostCode","Observed From":"2026-08-01","Observed To / Report Date":"2026-08-31","Reported / Historical ASN":"AS5607","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Residential proxy in successful token-use sequence","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N48","Notes":"Source observation scope: Late August 2026."},{"Type":"IPv4","Indicator":"152.89.162.138","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"152.89.162.139","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"155.117.117.34","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS215703","Reported / Historical Prefix":"","Current ASN":"AS215703","Current Prefix":"155.117.117.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"155.133.4.175","Campaign / Provider":"Console Chaos FortiGate management-interface exploitation","Observed From":"2024-11-16","Observed To / Report Date":"2025-01-10","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"","Current ASN":"AS62240","Current Prefix":"155.133.4.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"SSL VPN client and web management interface","Default Use":"Historical exact-IP hunt; prioritize exposed-management and SSL VPN telemetry over static blocking.","Source IDs":"N09","Notes":"Arctic Wolf observed VPS-origin HTTPS management activity, account creation, SSL VPN changes, and later DCSync."},{"Type":"IPv4","Indicator":"157.245.3.251","Campaign / Provider":"Console Chaos FortiGate management-interface exploitation","Observed From":"2024-11-16","Observed To / Report Date":"2025-01-10","Reported / Historical ASN":"AS14061","Reported / Historical Prefix":"","Current ASN":"AS14061","Current Prefix":"157.245.0.0/20","Current Country":"","Mapping Changed":"No","Telemetry Context":"SSL VPN client and web management interface","Default Use":"Historical exact-IP hunt; prioritize exposed-management and SSL VPN telemetry over static blocking.","Source IDs":"N09","Notes":"Arctic Wolf observed VPS-origin HTTPS management activity, account creation, SSL VPN changes, and later DCSync."},{"Type":"IPv4","Indicator":"158.255.208.155","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"158.255.211.165","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"162.210.196.101","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS30633","Reported / Historical Prefix":"","Current ASN":"AS30633","Current Prefix":"162.210.192.0/21","Current Country":"","Mapping Changed":"No","Telemetry Context":"Exfiltration","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"167.71.245.10","Campaign / Provider":"Console Chaos FortiGate management-interface exploitation","Observed From":"2024-11-16","Observed To / Report Date":"2025-01-10","Reported / Historical ASN":"AS14061","Reported / Historical Prefix":"","Current ASN":"AS14061","Current Prefix":"167.71.240.0/20","Current Country":"","Mapping Changed":"No","Telemetry Context":"SSL VPN client and web management interface","Default Use":"Historical exact-IP hunt; prioritize exposed-management and SSL VPN telemetry over static blocking.","Source IDs":"N09","Notes":"Arctic Wolf observed VPS-origin HTTPS management activity, account creation, SSL VPN changes, and later DCSync."},{"Type":"IPv4","Indicator":"170.130.165.42","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS62904","Reported / Historical Prefix":"","Current ASN":"AS62904","Current Prefix":"170.130.164.0/22","Current Country":"","Mapping Changed":"No","Telemetry Context":"Command and control","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"172.245.247.21","Campaign / Provider":"Kapibala","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS36352","Current Prefix":"","Current Country":"","Mapping Changed":"Current mapping added","Telemetry Context":"Exploitation","Default Use":"Exact-indicator hunt with campaign and observation-date context; revalidate routing and ownership before blocking.","Source IDs":"N39","Notes":"High, Shared hosting; no provider complicity established"},{"Type":"IPv4","Indicator":"172.67.214.35","Campaign / Provider":"ARToken / EvilTokens phishing infrastructure behind Cloudflare","Observed From":"2026-07-01","Observed To / Report Date":"2026-07-01","Reported / Historical ASN":"AS13335","Reported / Historical Prefix":"","Current ASN":"AS13335","Current Prefix":"172.67.208.0/20","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published campaign infrastructure; ASN attribution is context, not provider attribution","Default Use":"Short-TTL exact-IP hunt only; do not add or block the whole Cloudflare ASN.","Source IDs":"N20","Notes":"Keep exact infrastructure evidence separate from any claim of provider complicity."},{"Type":"IPv4","Indicator":"172.86.96.42","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS14956","Reported / Historical Prefix":"","Current ASN":"AS14956","Current Prefix":"172.86.96.0/21","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"172.96.10.212","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS64236","Reported / Historical Prefix":"","Current ASN":"AS64236","Current Prefix":"172.96.8.0/21","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"176.118.165.76","Campaign / Provider":"Gamaredon / Primitive Bear C2 or downloader infrastructure","Observed From":"","Observed To / Report Date":"2022-02-03","Reported / Historical ASN":"AS43830","Reported / Historical Prefix":"","Current ASN":"AS43830","Current Prefix":"176.118.165.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Malware C2/downloader infrastructure, not sign-in source","Default Use":"Historical exact-IP hunt; ASN only as contextual risk.","Source IDs":"S08, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"IPv4","Indicator":"176.123.1.250","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"176.123.175.242","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"176.123.6.58","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"176.253.248.175","Campaign / Provider":"GhostCode","Observed From":"2026-08-01","Observed To / Report Date":"2026-08-31","Reported / Historical ASN":"AS5607","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Residential proxy in successful token-use sequence","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N48","Notes":"Source observation scope: Late August 2026."},{"Type":"IPv4","Indicator":"176.31.252.121","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"176.53.133.249","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"176.53.133.0/24","Current ASN":"AS62240","Current Prefix":"176.53.133.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Proline IT Ltd; selectel.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"176.53.40.221","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"178.175.139.202","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"178.175.139.203","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"178.209.51.234","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"179.43.184.22","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"184.107.5.46","Campaign / Provider":"Akira and Fog ransomware via SonicWall SSL VPN","Observed From":"2024-08-01","Observed To / Report Date":"2024-10-24","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS32613","Current Prefix":"184.107.0.0/16","Current Country":"","Mapping Changed":"Not compared","Telemetry Context":"VPN client IP","Default Use":"Historical exact-IP hunt; correlate VPN login with rapid lateral movement, credential access, and encryption.","Source IDs":"N07","Notes":"Arctic Wolf reported hosting-related ASN use and a short interval from VPN access to ransomware impact."},{"Type":"IPv4","Indicator":"185.128.43.54","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"185.168.208.102","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS21249","Reported / Historical Prefix":"","Current ASN":"AS215540","Current Prefix":"185.168.208.0/24","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"185.174.100.199","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS8100","Reported / Historical Prefix":"","Current ASN":"AS36352","Current Prefix":"185.174.100.0/22","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"185.178.208.153","Campaign / Provider":"UNC6671 multi-brand vishing, AiTM, and SaaS extortion","Observed From":"2026-04-01","Observed To / Report Date":"2026-08-06","Reported / Historical ASN":"AS57724","Reported / Historical Prefix":"","Current ASN":"AS57724","Current Prefix":"185.178.208.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Phishing reverse proxy","Default Use":"Time-bounded exact-IP alert plus ASN context; revalidate current routing.","Source IDs":"N17","Notes":"GTIG warns that most source IPs are commercial VPN nodes and cycle quickly; prioritize TTP and session behavior."},{"Type":"IPv4","Indicator":"185.178.209.193","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"185.181.230.108","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS60602","Reported / Historical Prefix":"","Current ASN":"AS60602","Current Prefix":"185.181.230.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"185.184.192.108","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"185.235.137.150","Campaign / Provider":"Akira and Fog ransomware via SonicWall SSL VPN","Observed From":"2024-08-01","Observed To / Report Date":"2024-10-24","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS59711","Current Prefix":"185.235.137.0/24","Current Country":"","Mapping Changed":"Not compared","Telemetry Context":"VPN client IP","Default Use":"Historical exact-IP hunt; correlate VPN login with rapid lateral movement, credential access, and encryption.","Source IDs":"N07","Notes":"Arctic Wolf reported hosting-related ASN use and a short interval from VPN access to ransomware impact."},{"Type":"IPv4","Indicator":"185.247.71.106","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"185.247.71.107","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"185.253.98.242","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"185.253.98.243","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"185.33.86.2","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS202015","Reported / Historical Prefix":"","Current ASN":"AS202015","Current Prefix":"185.33.86.0/23","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"185.46.10.143","Campaign / Provider":"Gamaredon / Primitive Bear C2 or downloader infrastructure","Observed From":"","Observed To / Report Date":"2022-02-03","Reported / Historical ASN":"AS197695","Reported / Historical Prefix":"","Current ASN":"AS197695","Current Prefix":"185.46.10.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Malware C2/downloader infrastructure, not sign-in source","Default Use":"Historical exact-IP hunt; ASN only as contextual risk.","Source IDs":"S08, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"IPv4","Indicator":"185.65.205.82","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"185.81.126.157","Campaign / Provider":"EvilTokens post-compromise Microsoft 365 token replay","Observed From":"2026-04-06","Observed To / Report Date":"2026-04-06","Reported / Historical ASN":"AS136787","Reported / Historical Prefix":"","Current ASN":"AS136787","Current Prefix":"185.81.126.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published malicious-use infrastructure; provider involvement was not established","Default Use":"Historical exact-IP hunt plus ASN/anonymizer context; revalidate before blocking.","Source IDs":"N15","Notes":"Retain as time-bounded evidence and keep provider abuse separate from provider complicity."},{"Type":"IPv4","Indicator":"188.126.79.82","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"188.127.244.3","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"188.165.236.151","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"188.227.173.198","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"188.40.81.84","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"188.42.253.16","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"188.92.78.242","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"190.123.46.11","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"190.2.142.25","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"190.2.142.28","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"190.97.163.117","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"190.97.163.142","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"190.97.163.213","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"190.97.163.88","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"192.42.116.12","Campaign / Provider":"PAYLOAD ransomware","Observed From":"2026-04-11","Observed To / Report Date":"2026-04-16","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Listed IOC; individual IP role not specified","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N54","Notes":"Source observation scope: April 2026 incident; source published Sept21."},{"Type":"IPv4","Indicator":"192.42.116.50","Campaign / Provider":"PAYLOAD ransomware","Observed From":"2026-04-11","Observed To / Report Date":"2026-04-16","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Listed IOC; individual IP role not specified","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N54","Notes":"Source observation scope: April 2026 incident; source published Sept21."},{"Type":"IPv4","Indicator":"192.42.116.52","Campaign / Provider":"PAYLOAD ransomware","Observed From":"2026-04-11","Observed To / Report Date":"2026-04-16","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Listed IOC; individual IP role not specified","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N54","Notes":"Source observation scope: April 2026 incident; source published Sept21."},{"Type":"IPv4","Indicator":"192.42.116.56","Campaign / Provider":"PAYLOAD ransomware","Observed From":"2026-04-11","Observed To / Report Date":"2026-04-16","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Listed IOC; individual IP role not specified","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N54","Notes":"Source observation scope: April 2026 incident; source published Sept21."},{"Type":"IPv4","Indicator":"192.42.116.97","Campaign / Provider":"PAYLOAD ransomware","Observed From":"2026-04-11","Observed To / Report Date":"2026-04-16","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Listed IOC; individual IP role not specified","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N54","Notes":"Source observation scope: April 2026 incident; source published Sept21."},{"Type":"IPv4","Indicator":"192.71.211.77","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"192.71.249.70","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"192.99.0.114","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"193.105.134.152","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"193.106.31.98","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"193.106.31.99","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"193.160.216.60","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"193.160.216.0/24","Current ASN":"AS62240","Current Prefix":"193.160.216.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Proline IT Ltd; selectel.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"193.160.217.66","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"193.160.217.0/24","Current ASN":"AS62240","Current Prefix":"193.160.217.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Proline IT Ltd; selectel.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"193.163.194.7","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"","Current ASN":"AS62240","Current Prefix":"193.163.194.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"193.232.144.116","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"193.232.144.0/24","Current ASN":"AS209367","Current Prefix":"193.232.144.0/23","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Qwarta LLC; qwarta.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"193.239.236.149","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"","Current ASN":"AS62240","Current Prefix":"193.239.236.0/23","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"193.239.86.18","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"193.239.86.19","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"193.29.63.226","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS63473","Reported / Historical Prefix":"","Current ASN":"AS63473","Current Prefix":"193.29.63.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"193.34.212.132","Campaign / Provider":"UNC6671 multi-brand vishing, AiTM, and SaaS extortion","Observed From":"2026-04-01","Observed To / Report Date":"2026-08-06","Reported / Historical ASN":"AS201814","Reported / Historical Prefix":"","Current ASN":"AS201814","Current Prefix":"193.34.212.0/23","Current Country":"","Mapping Changed":"No","Telemetry Context":"Phishing-kit backend proxy","Default Use":"Time-bounded exact-IP alert plus ASN context; revalidate current routing.","Source IDs":"N17","Notes":"GTIG warns that most source IPs are commercial VPN nodes and cycle quickly; prioritize TTP and session behavior."},{"Type":"IPv4","Indicator":"193.5.65.114","Campaign / Provider":"Settra","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS207461","Current Prefix":"","Current Country":"","Mapping Changed":"Current mapping added","Telemetry Context":"MeshAgent C2","Default Use":"Exact-indicator hunt with campaign and observation-date context; revalidate routing and ownership before blocking.","Source IDs":"N41","Notes":"High, Repeated malicious workstation relationship described, but no provider complicity established, Activity window: September 2026"},{"Type":"IPv4","Indicator":"193.58.177.124","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"193.58.177.0/24","Current ASN":"AS62240","Current Prefix":"193.58.177.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Mastercom LLC; mastercommunications.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"194.180.174.46","Campaign / Provider":"Gamaredon / Primitive Bear C2 or downloader infrastructure","Observed From":"","Observed To / Report Date":"2022-02-03","Reported / Historical ASN":"AS39798","Reported / Historical Prefix":"","Current ASN":"AS39798","Current Prefix":"194.180.174.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Malware C2/downloader infrastructure, not sign-in source","Default Use":"Historical exact-IP hunt; ASN only as contextual risk.","Source IDs":"S08, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"IPv4","Indicator":"194.190.112.167","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"194.190.112.0/24","Current ASN":"AS219340","Current Prefix":"194.190.112.0/24","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Qwarta LLC; qwarta.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"194.190.179.10","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"194.190.179.0/24","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Qwarta LLC; qwarta.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"194.190.190.64","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"194.190.190.0/24","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Qwarta LLC; qwarta.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"194.190.90.41","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"194.190.90.0/24","Current ASN":"AS35645","Current Prefix":"194.190.90.0/23","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Qwarta LLC; qwarta.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"194.190.91.222","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"194.190.91.0/24","Current ASN":"AS35645","Current Prefix":"194.190.90.0/23","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Qwarta LLC; qwarta.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"194.226.185.120","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"194.226.185.0/24","Current ASN":"AS209367","Current Prefix":"194.226.184.0/23","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Qwarta LLC; qwarta.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"194.33.45.167","Campaign / Provider":"Akira and Fog ransomware via SonicWall SSL VPN","Observed From":"2024-08-01","Observed To / Report Date":"2024-10-24","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS62240","Current Prefix":"194.33.45.0/24","Current Country":"","Mapping Changed":"Not compared","Telemetry Context":"Exfiltration","Default Use":"Historical exact-IP hunt; correlate VPN login with rapid lateral movement, credential access, and encryption.","Source IDs":"N07","Notes":"Arctic Wolf reported hosting-related ASN use and a short interval from VPN access to ransomware impact."},{"Type":"IPv4","Indicator":"194.33.45.194","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"","Current ASN":"AS62240","Current Prefix":"194.33.45.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"194.58.92.102","Campaign / Provider":"Gamaredon / Primitive Bear C2 or downloader infrastructure","Observed From":"","Observed To / Report Date":"2022-02-03","Reported / Historical ASN":"AS197695","Reported / Historical Prefix":"","Current ASN":"AS197695","Current Prefix":"194.58.92.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Malware C2/downloader infrastructure, not sign-in source","Default Use":"Historical exact-IP hunt; ASN only as contextual risk.","Source IDs":"S08, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"IPv4","Indicator":"194.67.109.164","Campaign / Provider":"Gamaredon / Primitive Bear C2 or downloader infrastructure","Observed From":"","Observed To / Report Date":"2022-02-03","Reported / Historical ASN":"AS197695","Reported / Historical Prefix":"","Current ASN":"AS197695","Current Prefix":"194.67.109.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Malware C2/downloader infrastructure, not sign-in source","Default Use":"Historical exact-IP hunt; ASN only as contextual risk.","Source IDs":"S08, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"IPv4","Indicator":"195.140.213.114","Campaign / Provider":"UNC6671 multi-brand vishing, AiTM, and SaaS extortion","Observed From":"2026-04-01","Observed To / Report Date":"2026-08-06","Reported / Historical ASN":"AS25369","Reported / Historical Prefix":"","Current ASN":"AS25369","Current Prefix":"195.140.212.0/22","Current Country":"","Mapping Changed":"No","Telemetry Context":"Automated SaaS data exfiltration","Default Use":"Time-bounded exact-IP alert plus ASN context; revalidate current routing.","Source IDs":"N17","Notes":"GTIG warns that most source IPs are commercial VPN nodes and cycle quickly; prioritize TTP and session behavior."},{"Type":"IPv4","Indicator":"195.140.213.115","Campaign / Provider":"UNC6671 multi-brand vishing, AiTM, and SaaS extortion","Observed From":"2026-04-01","Observed To / Report Date":"2026-08-06","Reported / Historical ASN":"AS25369","Reported / Historical Prefix":"","Current ASN":"AS25369","Current Prefix":"195.140.212.0/22","Current Country":"","Mapping Changed":"No","Telemetry Context":"Automated SaaS data exfiltration","Default Use":"Time-bounded exact-IP alert plus ASN context; revalidate current routing.","Source IDs":"N17","Notes":"GTIG warns that most source IPs are commercial VPN nodes and cycle quickly; prioritize TTP and session behavior."},{"Type":"IPv4","Indicator":"195.19.209.226","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"195.19.209.0/24","Current ASN":"AS197695","Current Prefix":"195.19.209.0/24","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Qwarta LLC; qwarta.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"195.206.107.202","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"195.206.107.203","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"198.50.157.109","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"199.71.233.178","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"2.56.190.139","Campaign / Provider":"SharePoint ToolShell exploitation infrastructure in PacketHub-assigned space","Observed From":"2025-07-22","Observed To / Report Date":"2025-07-22","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"","Current ASN":"AS62240","Current Prefix":"2.56.190.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Published malicious-use infrastructure; provider involvement was not established","Default Use":"Historical exact-IP hunt plus ASN/anonymizer context; revalidate before blocking.","Source IDs":"N16","Notes":"Retain as time-bounded evidence and keep provider abuse separate from provider complicity."},{"Type":"IPv4","Indicator":"2.57.241.246","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-02-01","Observed To / Report Date":"2026-02-28","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS43180","Current Prefix":"2.57.241.0/24","Current Country":"","Mapping Changed":"Current mapping added","Telemetry Context":"CosmicPulse downloader DLL host","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N55","Notes":"Source observation scope: 2026-02."},{"Type":"IPv4","Indicator":"206.168.190.143","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS14315","Reported / Historical Prefix":"","Current ASN":"AS14315","Current Prefix":"206.168.190.0/23","Current Country":"","Mapping Changed":"No","Telemetry Context":"Exfiltration","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"207.188.6.17","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS396356","Reported / Historical Prefix":"","Current ASN":"AS396356","Current Prefix":"207.188.6.0/23","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"208.115.232.194","Campaign / Provider":"Akira and Fog ransomware via SonicWall SSL VPN","Observed From":"2024-08-01","Observed To / Report Date":"2024-10-24","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS46475","Current Prefix":"208.115.232.0/24","Current Country":"","Mapping Changed":"Not compared","Telemetry Context":"VPN client IP","Default Use":"Historical exact-IP hunt; correlate VPN login with rapid lateral movement, credential access, and encryption.","Source IDs":"N07","Notes":"Arctic Wolf reported hosting-related ASN use and a short interval from VPN access to ransomware impact."},{"Type":"IPv4","Indicator":"209.58.131.32","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"212.109.199.204","Campaign / Provider":"Gamaredon / Primitive Bear C2 or downloader infrastructure","Observed From":"","Observed To / Report Date":"2022-02-03","Reported / Historical ASN":"AS29182","Reported / Historical Prefix":"","Current ASN":"AS29182","Current Prefix":"212.109.198.0/23","Current Country":"","Mapping Changed":"No","Telemetry Context":"Malware C2/downloader infrastructure, not sign-in source","Default Use":"Historical exact-IP hunt; ASN only as contextual risk.","Source IDs":"S08, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"IPv4","Indicator":"212.193.136.39","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"212.193.136.0/24","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Qwarta LLC; qwarta.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"212.193.137.253","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"212.193.137.0/24","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Qwarta LLC; qwarta.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"212.193.140.208","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"212.193.140.0/24","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Qwarta LLC; qwarta.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"212.193.143.60","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"212.193.143.0/24","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Qwarta LLC; qwarta.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"212.7.217.5","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"213.128.89.184","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"213.139.193.38","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"213.139.193.0/24","Current ASN":"AS62240","Current Prefix":"213.139.193.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Admin LLC; cadmin.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"217.12.219.11","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"217.182.199.126","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"217.23.1.110","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"23.227.162.18","Campaign / Provider":"Akira and Fog ransomware via SonicWall SSL VPN","Observed From":"2024-08-01","Observed To / Report Date":"2024-10-24","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS29802","Current Prefix":"23.227.162.0/24","Current Country":"","Mapping Changed":"Not compared","Telemetry Context":"Exfiltration","Default Use":"Historical exact-IP hunt; correlate VPN login with rapid lateral movement, credential access, and encryption.","Source IDs":"N07","Notes":"Arctic Wolf reported hosting-related ASN use and a short interval from VPN access to ransomware impact."},{"Type":"IPv4","Indicator":"23.229.53.52","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS55286","Reported / Historical Prefix":"23.229.52.0/22","Current ASN":"AS55286","Current Prefix":"23.229.52.0/22","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"B2 Net Solutions Inc.; servermania.com. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"23.229.53.63","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS55286","Reported / Historical Prefix":"23.229.52.0/22","Current ASN":"AS55286","Current Prefix":"23.229.52.0/22","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"B2 Net Solutions Inc.; servermania.com. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"23.229.67.247","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS55286","Reported / Historical Prefix":"23.229.64.0/22","Current ASN":"AS55286","Current Prefix":"23.229.67.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"B2 Net Solutions Inc.; servermania.com. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"23.229.67.248","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS55286","Reported / Historical Prefix":"23.229.64.0/22","Current ASN":"AS55286","Current Prefix":"23.229.67.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"B2 Net Solutions Inc.; servermania.com. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"23.229.79.18","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS55286","Reported / Historical Prefix":"23.229.72.0/21","Current ASN":"AS55286","Current Prefix":"23.229.79.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"B2 Net Solutions Inc.; servermania.com. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"23.229.79.24","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS55286","Reported / Historical Prefix":"23.229.72.0/21","Current ASN":"AS55286","Current Prefix":"23.229.79.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"B2 Net Solutions Inc.; servermania.com. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"23.229.79.25","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS55286","Reported / Historical Prefix":"23.229.72.0/21","Current ASN":"AS55286","Current Prefix":"23.229.79.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"B2 Net Solutions Inc.; servermania.com. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"23.229.79.28","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS55286","Reported / Historical Prefix":"23.229.72.0/21","Current ASN":"AS55286","Current Prefix":"23.229.79.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"B2 Net Solutions Inc.; servermania.com. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"23.234.75.84","Campaign / Provider":"UNC6671 multi-brand vishing, AiTM, and SaaS extortion","Observed From":"2026-04-01","Observed To / Report Date":"2026-08-06","Reported / Historical ASN":"AS11878","Reported / Historical Prefix":"","Current ASN":"AS11878","Current Prefix":"23.234.75.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Automated SaaS data exfiltration","Default Use":"Time-bounded exact-IP alert plus ASN context; revalidate current routing.","Source IDs":"N17","Notes":"GTIG warns that most source IPs are commercial VPN nodes and cycle quickly; prioritize TTP and session behavior."},{"Type":"IPv4","Indicator":"23.27.140.65","Campaign / Provider":"Console Chaos FortiGate management-interface exploitation","Observed From":"2024-11-16","Observed To / Report Date":"2025-01-10","Reported / Historical ASN":"AS149440","Reported / Historical Prefix":"","Current ASN":"AS149440","Current Prefix":"23.27.140.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"SSL VPN client and web management interface","Default Use":"Historical exact-IP hunt; prioritize exposed-management and SSL VPN telemetry over static blocking.","Source IDs":"N09","Notes":"Arctic Wolf observed VPS-origin HTTPS management activity, account creation, SSL VPN changes, and later DCSync."},{"Type":"IPv4","Indicator":"23.94.54.125","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS36352","Reported / Historical Prefix":"","Current ASN":"AS36352","Current Prefix":"23.94.48.0/21","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"31.135.14.182","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"31.192.107.165","Campaign / Provider":"Console Chaos FortiGate management-interface exploitation","Observed From":"2024-11-16","Observed To / Report Date":"2025-01-10","Reported / Historical ASN":"AS50867","Reported / Historical Prefix":"","Current ASN":"AS50867","Current Prefix":"31.192.107.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"SSL VPN client","Default Use":"Historical exact-IP hunt; prioritize exposed-management and SSL VPN telemetry over static blocking.","Source IDs":"N09","Notes":"Arctic Wolf observed VPS-origin HTTPS management activity, account creation, SSL VPN changes, and later DCSync."},{"Type":"IPv4","Indicator":"31.210.70.184","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"31.210.70.186","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"31.210.70.190","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"31.222.247.64","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"","Current ASN":"AS62240","Current Prefix":"31.222.247.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"31.7.56.52","Campaign / Provider":"UNC6671 multi-brand vishing, AiTM, and SaaS extortion","Observed From":"2026-04-01","Observed To / Report Date":"2026-08-06","Reported / Historical ASN":"AS51852","Reported / Historical Prefix":"","Current ASN":"AS51852","Current Prefix":"31.7.56.0/21","Current Country":"","Mapping Changed":"No","Telemetry Context":"Panel AiTM reverse proxy","Default Use":"Time-bounded exact-IP alert plus ASN context; revalidate current routing.","Source IDs":"N17","Notes":"GTIG warns that most source IPs are commercial VPN nodes and cycle quickly; prioritize TTP and session behavior."},{"Type":"IPv4","Indicator":"31.7.56.61","Campaign / Provider":"UNC6671 multi-brand vishing, AiTM, and SaaS extortion","Observed From":"2026-04-01","Observed To / Report Date":"2026-08-06","Reported / Historical ASN":"AS51852","Reported / Historical Prefix":"","Current ASN":"AS51852","Current Prefix":"31.7.56.0/21","Current Country":"","Mapping Changed":"No","Telemetry Context":"Panel AiTM reverse proxy","Default Use":"Time-bounded exact-IP alert plus ASN context; revalidate current routing.","Source IDs":"N17","Notes":"GTIG warns that most source IPs are commercial VPN nodes and cycle quickly; prioritize TTP and session behavior."},{"Type":"IPv4","Indicator":"34.153.223.102","Campaign / Provider":"Storm-3168","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS396982","Current Prefix":"34.153.192.0/19","Current Country":"","Mapping Changed":"Current mapping added","Telemetry Context":"App Service probing","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N52","Notes":"Source observation scope: Early 2026 probing; early June2026 ARM incident."},{"Type":"IPv4","Indicator":"37.120.143.202","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"37.120.143.203","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"37.140.199.20","Campaign / Provider":"Gamaredon / Primitive Bear C2 or downloader infrastructure","Observed From":"","Observed To / Report Date":"2022-02-03","Reported / Historical ASN":"AS197695","Reported / Historical Prefix":"","Current ASN":"AS197695","Current Prefix":"37.140.199.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Malware C2/downloader infrastructure, not sign-in source","Default Use":"Historical exact-IP hunt; ASN only as contextual risk.","Source IDs":"S08, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"IPv4","Indicator":"37.19.196.65","Campaign / Provider":"Console Chaos FortiGate management-interface exploitation","Observed From":"2024-11-16","Observed To / Report Date":"2025-01-10","Reported / Historical ASN":"AS212238","Reported / Historical Prefix":"","Current ASN":"AS212238","Current Prefix":"37.19.196.0/23","Current Country":"","Mapping Changed":"No","Telemetry Context":"Web management interface","Default Use":"Historical exact-IP hunt; prioritize exposed-management and SSL VPN telemetry over static blocking.","Source IDs":"N09","Notes":"Arctic Wolf observed VPS-origin HTTPS management activity, account creation, SSL VPN changes, and later DCSync."},{"Type":"IPv4","Indicator":"37.19.210.12","Campaign / Provider":"PAYLOAD ransomware","Observed From":"2026-04-11","Observed To / Report Date":"2026-04-16","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Listed IOC; individual IP role not specified","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N54","Notes":"Source observation scope: April 2026 incident; source published Sept21."},{"Type":"IPv4","Indicator":"37.235.55.113","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"37.235.60.141","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"38.114.123.167","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS63023","Reported / Historical Prefix":"","Current ASN":"AS63023","Current Prefix":"38.114.123.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"38.114.123.229","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS63023","Reported / Historical Prefix":"","Current ASN":"AS63023","Current Prefix":"38.114.123.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"38.42.59.171","Campaign / Provider":"UNC6671 multi-brand vishing, AiTM, and SaaS extortion","Observed From":"2026-04-01","Observed To / Report Date":"2026-08-06","Reported / Historical ASN":"AS395354","Reported / Historical Prefix":"","Current ASN":"AS395354","Current Prefix":"38.42.32.0/19","Current Country":"","Mapping Changed":"No","Telemetry Context":"M365 / Okta residential proxy","Default Use":"Short-TTL exact-IP hunt only; do not block the residential ASN.","Source IDs":"N17","Notes":"GTIG warns that most source IPs are commercial VPN nodes and cycle quickly; prioritize TTP and session behavior."},{"Type":"IPv4","Indicator":"45.11.59.16","Campaign / Provider":"Akira and Fog ransomware via SonicWall SSL VPN","Observed From":"2024-08-01","Observed To / Report Date":"2024-10-24","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS43641","Current Prefix":"45.11.59.0/24","Current Country":"","Mapping Changed":"Not compared","Telemetry Context":"VPN client IP","Default Use":"Historical exact-IP hunt; correlate VPN login with rapid lateral movement, credential access, and encryption.","Source IDs":"N07","Notes":"Arctic Wolf reported hosting-related ASN use and a short interval from VPN access to ransomware impact."},{"Type":"IPv4","Indicator":"45.12.222.150","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"45.13.122.7","Campaign / Provider":"Settra","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS31034","Current Prefix":"","Current Country":"","Mapping Changed":"Current mapping added","Telemetry Context":"MeshAgent C2","Default Use":"Exact-indicator hunt with campaign and observation-date context; revalidate routing and ownership before blocking.","Source IDs":"N41","Notes":"High, Aruba shared hosting; preserve exact-IP scope, Activity window: July 2026"},{"Type":"IPv4","Indicator":"45.131.66.106","Campaign / Provider":"Storm-3168","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS213250","Current Prefix":"45.131.66.0/23","Current Country":"","Mapping Changed":"Current mapping added","Telemetry Context":"App Service probing and malicious ARM requests","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N52","Notes":"Source observation scope: Early 2026 probing; early June2026 ARM incident."},{"Type":"IPv4","Indicator":"45.55.158.47","Campaign / Provider":"Console Chaos FortiGate management-interface exploitation","Observed From":"2024-11-16","Observed To / Report Date":"2025-01-10","Reported / Historical ASN":"AS14061","Reported / Historical Prefix":"","Current ASN":"AS14061","Current Prefix":"45.55.128.0/18","Current Country":"","Mapping Changed":"No","Telemetry Context":"SSL VPN client and web management interface","Default Use":"Historical exact-IP hunt; prioritize exposed-management and SSL VPN telemetry over static blocking.","Source IDs":"N09","Notes":"Arctic Wolf observed VPS-origin HTTPS management activity, account creation, SSL VPN changes, and later DCSync."},{"Type":"IPv4","Indicator":"45.55.76.210","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS14061","Reported / Historical Prefix":"","Current ASN":"AS14061","Current Prefix":"45.55.64.0/19","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"45.56.163.58","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS8100","Reported / Historical Prefix":"","Current ASN":"AS199959","Current Prefix":"45.56.163.0/24","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"45.66.249.93","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS62005","Reported / Historical Prefix":"","Current ASN":"AS62005","Current Prefix":"45.66.249.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"45.84.59.66","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-04-01","Observed To / Report Date":"2026-04-30","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS212477","Current Prefix":"45.84.59.0/24","Current Country":"","Mapping Changed":"Current mapping added","Telemetry Context":"CosmicPulse downloader DLL host","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N55","Notes":"Source observation scope: 2026-04."},{"Type":"IPv4","Indicator":"45.86.208.146","Campaign / Provider":"Akira and Fog ransomware via SonicWall SSL VPN","Observed From":"2024-08-01","Observed To / Report Date":"2024-10-24","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS62240","Current Prefix":"45.86.208.0/22","Current Country":"","Mapping Changed":"Not compared","Telemetry Context":"FileZilla exfiltration","Default Use":"Historical exact-IP hunt; correlate VPN login with rapid lateral movement, credential access, and encryption.","Source IDs":"N07","Notes":"Arctic Wolf reported hosting-related ASN use and a short interval from VPN access to ransomware impact."},{"Type":"IPv4","Indicator":"45.87.124.155","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"45.87.124.0/24","Current ASN":"AS62240","Current Prefix":"45.87.124.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Auction LLC; dauction.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"46.105.107.231","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"46.105.79.45","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"46.148.16.138","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"47.218.103.146","Campaign / Provider":"UNC6671 multi-brand vishing, AiTM, and SaaS extortion","Observed From":"2026-04-01","Observed To / Report Date":"2026-08-06","Reported / Historical ASN":"AS19108","Reported / Historical Prefix":"","Current ASN":"AS19108","Current Prefix":"47.218.0.0/17","Current Country":"","Mapping Changed":"No","Telemetry Context":"M365 / Okta residential proxy","Default Use":"Short-TTL exact-IP hunt only; do not block the residential ASN.","Source IDs":"N17","Notes":"GTIG warns that most source IPs are commercial VPN nodes and cycle quickly; prioritize TTP and session behavior."},{"Type":"IPv4","Indicator":"49.12.133.165","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"49.50.66.72","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"5.135.164.8","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"5.181.234.56","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"5.181.234.58","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"5.181.234.59","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"5.188.163.34","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"5.230.71.51","Campaign / Provider":"GhostCode","Observed From":"2026-08-01","Observed To / Report Date":"2026-08-31","Reported / Historical ASN":"AS12586","Reported / Historical Prefix":"","Current ASN":"AS12586","Current Prefix":"5.230.71.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Final successful Intune enrollment","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N48","Notes":"Source observation scope: Late August 2026."},{"Type":"IPv4","Indicator":"51.161.128.135","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"51.38.66.162","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"51.75.34.158","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"51.79.111.220","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"51.79.208.134","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"51.81.45.12","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS16276","Reported / Historical Prefix":"51.81.0.0/17","Current ASN":"AS16276","Current Prefix":"51.81.0.0/17","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"OVH US LLC; ovh.com. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"51.81.45.128","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS16276","Reported / Historical Prefix":"51.81.0.0/17","Current ASN":"AS16276","Current Prefix":"51.81.0.0/17","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"OVH US LLC; ovh.com. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"54.37.200.68","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"57.128.101.78","Campaign / Provider":"Akira and Fog ransomware via SonicWall SSL VPN","Observed From":"2024-08-01","Observed To / Report Date":"2024-10-24","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS16276","Current Prefix":"57.128.0.0/17","Current Country":"","Mapping Changed":"Not compared","Telemetry Context":"AnyDesk command and control","Default Use":"Historical exact-IP hunt; correlate VPN login with rapid lateral movement, credential access, and encryption.","Source IDs":"N07","Notes":"Arctic Wolf reported hosting-related ASN use and a short interval from VPN access to ransomware impact."},{"Type":"IPv4","Indicator":"62.112.8.202","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"62.76.147.106","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"","Current ASN":"AS209367","Current Prefix":"62.76.146.0/23","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"62.76.147.174","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"62.76.147.0/24","Current ASN":"AS209367","Current Prefix":"62.76.146.0/23","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Qwarta LLC; qwarta.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"62.76.153.235","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"62.76.153.0/24","Current ASN":"AS199365","Current Prefix":"62.76.153.0/24","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Qwarta LLC; qwarta.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"64.190.113.25","Campaign / Provider":"Console Chaos FortiGate management-interface exploitation","Observed From":"2024-11-16","Observed To / Report Date":"2025-01-10","Reported / Historical ASN":"AS399629","Reported / Historical Prefix":"","Current ASN":"AS399629","Current Prefix":"64.190.113.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Web management interface","Default Use":"Historical exact-IP hunt; prioritize exposed-management and SSL VPN telemetry over static blocking.","Source IDs":"N09","Notes":"Arctic Wolf observed VPS-origin HTTPS management activity, account creation, SSL VPN changes, and later DCSync."},{"Type":"IPv4","Indicator":"64.190.76.14","Campaign / Provider":"PAYLOAD ransomware","Observed From":"2026-04-11","Observed To / Report Date":"2026-04-16","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Listed IOC; individual IP role not specified","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N54","Notes":"Source observation scope: April 2026 incident; source published Sept21."},{"Type":"IPv4","Indicator":"64.20.53.230","Campaign / Provider":"Storm-3168","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS19318","Current Prefix":"64.20.32.0/19","Current Country":"","Mapping Changed":"Current mapping added","Telemetry Context":"App Service probing","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N52","Notes":"Source observation scope: Early 2026 probing; early June2026 ARM incident."},{"Type":"IPv4","Indicator":"66.135.27.178","Campaign / Provider":"Console Chaos FortiGate management-interface exploitation","Observed From":"2024-11-16","Observed To / Report Date":"2025-01-10","Reported / Historical ASN":"AS20473","Reported / Historical Prefix":"","Current ASN":"AS20473","Current Prefix":"66.135.0.0/19","Current Country":"","Mapping Changed":"No","Telemetry Context":"SSL VPN client and web management interface","Default Use":"Historical exact-IP hunt; prioritize exposed-management and SSL VPN telemetry over static blocking.","Source IDs":"N09","Notes":"Arctic Wolf observed VPS-origin HTTPS management activity, account creation, SSL VPN changes, and later DCSync."},{"Type":"IPv4","Indicator":"66.181.33.32","Campaign / Provider":"Akira and Fog ransomware via SonicWall SSL VPN","Observed From":"2024-08-01","Observed To / Report Date":"2024-10-24","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS64236","Current Prefix":"66.181.32.0/19","Current Country":"","Mapping Changed":"Not compared","Telemetry Context":"VPN client IP","Default Use":"Historical exact-IP hunt; correlate VPN login with rapid lateral movement, credential access, and encryption.","Source IDs":"N07","Notes":"Arctic Wolf reported hosting-related ASN use and a short interval from VPN access to ransomware impact."},{"Type":"IPv4","Indicator":"66.70.179.236","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"70.34.198.226","Campaign / Provider":"Gamaredon / Primitive Bear C2 or downloader infrastructure","Observed From":"","Observed To / Report Date":"2022-02-03","Reported / Historical ASN":"AS20473","Reported / Historical Prefix":"","Current ASN":"AS20473","Current Prefix":"70.34.192.0/19","Current Country":"","Mapping Changed":"No","Telemetry Context":"Malware C2/downloader infrastructure, not sign-in source","Default Use":"Historical exact-IP hunt; ASN only as contextual risk.","Source IDs":"S08, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"IPv4","Indicator":"74.48.66.73","Campaign / Provider":"Kapibala","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS54004","Current Prefix":"","Current Country":"","Mapping Changed":"Current mapping added","Telemetry Context":"Staging","Default Use":"Exact-indicator hunt with campaign and observation-date context; revalidate routing and ownership before blocking.","Source IDs":"N39","Notes":"High, ISP origin; endpoint-only evidence"},{"Type":"IPv4","Indicator":"76.103.148.180","Campaign / Provider":"UNC6671 multi-brand vishing, AiTM, and SaaS extortion","Observed From":"2026-04-01","Observed To / Report Date":"2026-08-06","Reported / Historical ASN":"AS7922","Reported / Historical Prefix":"","Current ASN":"AS7922","Current Prefix":"76.96.0.0/11","Current Country":"","Mapping Changed":"No","Telemetry Context":"M365 / Okta residential proxy","Default Use":"Short-TTL exact-IP hunt only; do not block the residential ASN.","Source IDs":"N17","Notes":"GTIG warns that most source IPs are commercial VPN nodes and cycle quickly; prioritize TTP and session behavior."},{"Type":"IPv4","Indicator":"77.246.157.26","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"77.247.126.158","Campaign / Provider":"Akira and Fog ransomware via SonicWall SSL VPN","Observed From":"2024-08-01","Observed To / Report Date":"2024-10-24","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS62240","Current Prefix":"77.247.126.0/24","Current Country":"","Mapping Changed":"Not compared","Telemetry Context":"VPN client IP","Default Use":"Historical exact-IP hunt; correlate VPN login with rapid lateral movement, credential access, and encryption.","Source IDs":"N07","Notes":"Arctic Wolf reported hosting-related ASN use and a short interval from VPN access to ransomware impact."},{"Type":"IPv4","Indicator":"77.247.126.239","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"","Current ASN":"AS62240","Current Prefix":"77.247.126.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"77.83.247.80","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"77.83.247.81","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"77.83.4.102","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"77.83.4.0/24","Current ASN":"AS62240","Current Prefix":"77.83.4.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Proline IT Ltd; selectel.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"77.83.5.161","Campaign / Provider":"Proofpoint cloud credential compromise","Observed From":"2022-02-22","Observed To / Report Date":"2022-02-28","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"77.83.5.0/24","Current ASN":"AS62240","Current Prefix":"77.83.5.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Cloud sign-in brute-force/password spray source","Default Use":"Historical exact-IP hunt plus ASN context; revalidate current routing.","Source IDs":"S04, S06","Notes":"Proline IT Ltd; selectel.ru. Proofpoint published the exact IP, not the ASN or prefix."},{"Type":"IPv4","Indicator":"79.137.69.34","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"79.141.160.33","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS202015","Reported / Historical Prefix":"","Current ASN":"AS202015","Current Prefix":"79.141.160.0/23","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"79.141.173.235","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS202015","Reported / Historical Prefix":"","Current ASN":"AS202015","Current Prefix":"79.141.173.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"79.141.173.238","Campaign / Provider":"Akira and Fog ransomware via SonicWall SSL VPN","Observed From":"2024-08-01","Observed To / Report Date":"2024-10-24","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS202015","Current Prefix":"79.141.173.0/24","Current Country":"","Mapping Changed":"Not compared","Telemetry Context":"AnyDesk connection IP","Default Use":"Historical exact-IP hunt; correlate VPN login with rapid lateral movement, credential access, and encryption.","Source IDs":"N07","Notes":"Arctic Wolf reported hosting-related ASN use and a short interval from VPN access to ransomware impact."},{"Type":"IPv4","Indicator":"80.78.241.253","Campaign / Provider":"Gamaredon / Primitive Bear C2 or downloader infrastructure","Observed From":"","Observed To / Report Date":"2022-02-03","Reported / Historical ASN":"AS197695","Reported / Historical Prefix":"","Current ASN":"AS197695","Current Prefix":"80.78.241.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Malware C2/downloader infrastructure, not sign-in source","Default Use":"Historical exact-IP hunt; ASN only as contextual risk.","Source IDs":"S08, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"IPv4","Indicator":"80.90.39.95","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"80.90.55.44","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"81.96.174.54","Campaign / Provider":"GhostCode","Observed From":"2026-08-01","Observed To / Report Date":"2026-08-31","Reported / Historical ASN":"AS5089","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Residential proxy in successful token-use sequence","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N48","Notes":"Source observation scope: Late August 2026."},{"Type":"IPv4","Indicator":"82.146.50.52","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"82.202.160.36","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"82.33.39.74","Campaign / Provider":"GhostCode","Observed From":"2026-08-01","Observed To / Report Date":"2026-08-31","Reported / Historical ASN":"AS5089","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Residential proxy in successful token-use sequence","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N48","Notes":"Source observation scope: Late August 2026."},{"Type":"IPv4","Indicator":"83.229.17.123","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"","Current ASN":"AS62240","Current Prefix":"83.229.17.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"83.229.17.135","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"","Current ASN":"AS62240","Current Prefix":"83.229.17.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"83.229.17.148","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS62240","Reported / Historical Prefix":"","Current ASN":"AS62240","Current Prefix":"83.229.17.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"86.105.25.218","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"86.105.25.219","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"86.132.13.219","Campaign / Provider":"GhostCode","Observed From":"2026-08-01","Observed To / Report Date":"2026-08-31","Reported / Historical ASN":"AS2856","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Residential proxy in successful token-use sequence","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N48","Notes":"Source observation scope: Late August 2026."},{"Type":"IPv4","Indicator":"88.150.220.248","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"89.108.64.88","Campaign / Provider":"Gamaredon / Primitive Bear C2 or downloader infrastructure","Observed From":"","Observed To / Report Date":"2022-02-03","Reported / Historical ASN":"AS197695","Reported / Historical Prefix":"","Current ASN":"AS197695","Current Prefix":"89.108.64.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Malware C2/downloader infrastructure, not sign-in source","Default Use":"Historical exact-IP hunt; ASN only as contextual risk.","Source IDs":"S08, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"IPv4","Indicator":"89.108.78.82","Campaign / Provider":"Gamaredon / Primitive Bear C2 or downloader infrastructure","Observed From":"","Observed To / Report Date":"2022-02-03","Reported / Historical ASN":"AS197695","Reported / Historical Prefix":"","Current ASN":"AS197695","Current Prefix":"89.108.78.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Malware C2/downloader infrastructure, not sign-in source","Default Use":"Historical exact-IP hunt; ASN only as contextual risk.","Source IDs":"S08, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"IPv4","Indicator":"89.108.98.125","Campaign / Provider":"Gamaredon / Primitive Bear C2 or downloader infrastructure","Observed From":"","Observed To / Report Date":"2022-02-03","Reported / Historical ASN":"AS197695","Reported / Historical Prefix":"","Current ASN":"AS197695","Current Prefix":"89.108.98.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Malware C2/downloader infrastructure, not sign-in source","Default Use":"Historical exact-IP hunt; ASN only as contextual risk.","Source IDs":"S08, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"IPv4","Indicator":"89.125.209.168","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-02-01","Observed To / Report Date":"2026-02-28","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"AS212477","Current Prefix":"89.125.209.0/24","Current Country":"","Mapping Changed":"Current mapping added","Telemetry Context":"CosmicPulse downloader DLL host","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N55","Notes":"Source observation scope: 2026-02."},{"Type":"IPv4","Indicator":"89.38.224.2","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"89.38.224.3","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"90.215.55.70","Campaign / Provider":"GhostCode","Observed From":"2026-08-01","Observed To / Report Date":"2026-08-31","Reported / Historical ASN":"AS5607","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Residential proxy in successful token-use sequence","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N48","Notes":"Source observation scope: Late August 2026."},{"Type":"IPv4","Indicator":"91.132.139.66","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"91.132.139.67","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"91.191.214.170","Campaign / Provider":"Akira ransomware targeting SonicWall SSL VPN","Observed From":"2025-07-22","Observed To / Report Date":"2025-09-22","Reported / Historical ASN":"AS29802","Reported / Historical Prefix":"","Current ASN":"AS29802","Current Prefix":"91.191.214.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN client IP","Default Use":"Time-bounded exact-IP alert or hunt. Use the ASN as identity-risk context, not provider attribution.","Source IDs":"N06","Notes":"Arctic Wolf says the hosting networks are not inherently malicious and recommends limiting any blocking to VPN authentication."},{"Type":"IPv4","Indicator":"91.193.5.90","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"91.193.5.91","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"91.232.29.114","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"92.223.66.103","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"92.38.148.58","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"92.38.162.11","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"92.38.162.4","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"92.38.180.39","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"92.38.186.86","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"92.40.47.84","Campaign / Provider":"GhostCode","Observed From":"2026-08-01","Observed To / Report Date":"2026-08-31","Reported / Historical ASN":"AS206067","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Residential proxy in successful token-use sequence","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N48","Notes":"Source observation scope: Late August 2026."},{"Type":"IPv4","Indicator":"93.113.36.137","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"93.113.36.142","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"93.190.142.7","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"94.185.85.210","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"94.23.218.129","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"94.23.27.208","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"94.242.253.11","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"94.242.253.13","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"94.242.254.43","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"94.242.254.54","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"94.242.254.8","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"94.26.226.75","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"94.9.97.142","Campaign / Provider":"GhostCode","Observed From":"2026-08-01","Observed To / Report Date":"2026-08-31","Reported / Historical ASN":"AS5607","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Requires current routing verification","Telemetry Context":"Residential proxy in successful token-use sequence","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N48","Notes":"Source observation scope: Late August 2026."},{"Type":"IPv4","Indicator":"95.141.32.237","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"95.179.221.147","Campaign / Provider":"Gamaredon / Primitive Bear C2 or downloader infrastructure","Observed From":"","Observed To / Report Date":"2022-02-03","Reported / Historical ASN":"AS20473","Reported / Historical Prefix":"","Current ASN":"AS20473","Current Prefix":"95.179.208.0/20","Current Country":"","Mapping Changed":"No","Telemetry Context":"Malware C2/downloader infrastructure, not sign-in source","Default Use":"Historical exact-IP hunt; ASN only as contextual risk.","Source IDs":"S08, S06","Notes":"Current ASN/prefix mapping checked 2026-09-15 using RIPEstat network-info."},{"Type":"IPv4","Indicator":"95.213.164.11","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"95.213.164.12","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Ransomware-access VPN exit listed as current in May 2026 FBI FLASH","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"95.215.61.192","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"95.216.15.11","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"IPv4","Indicator":"95.216.15.25","Campaign / Provider":"First VPN Service (1VPNS)","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not checked; historical","Telemetry Context":"Historical ransomware-access VPN exit","Default Use":"Historical retro-hunt only; require current routing and service corroboration before blocking.","Source IDs":"N45","Notes":"FBI warns cloud IP reassignment requires current corroboration. Underlying hosts are not thereby sanctioned or BPH. Source applies to First VPN Service only, not similar names."},{"Type":"MD5","Indicator":"0108656A3E1ADE6CA4F21B084F5E1208","Campaign / Provider":"PAYLOAD ransomware","Observed From":"2026-04-11","Observed To / Report Date":"2026-04-16","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"killer.exe process killer","Default Use":"Exact-indicator hunt plus behavior; filenames/GPO names alone are weak indicators.","Source IDs":"N54","Notes":"Source observation scope: 2026-04-13."},{"Type":"MD5","Indicator":"BEA5E267F24D7DA59F6821BFFDBFF293","Campaign / Provider":"PAYLOAD ransomware","Observed From":"2026-04-11","Observed To / Report Date":"2026-04-16","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"kill.exe process killer","Default Use":"Exact-indicator hunt plus behavior; filenames/GPO names alone are weak indicators.","Source IDs":"N54","Notes":"Source observation scope: 2026-04-13."},{"Type":"SHA-256","Indicator":"8a01bcb70ec1c101a163c9cb8e074781c1322096f7ae01789f02252854def44c","Campaign / Provider":"Doko Panel / UNC6661 and ShinyHunters cluster","Observed From":"2025-11-01","Observed To / Report Date":"2026-04-30","Reported / Historical ASN":"AS201814","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"client.js phishing-panel artifact","Default Use":"Match file and web-content telemetry; preserve campaign and hosting context.","Source IDs":"N18","Notes":"Push lists the cluster timeframe as November 2025 through April 2026."},{"Type":"SHA-256","Indicator":"9c0939960e49122196e44b6779fe55dd7a13ab437ce251c8cf35f8c6daf8be21","Campaign / Provider":"Doko-derived heartbeat panel / UNC6671 and BlackFile cluster","Observed From":"2025-12-01","Observed To / Report Date":"2026-01-31","Reported / Historical ASN":"AS39287","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"client.js phishing-panel artifact","Default Use":"Match file and web-content telemetry; preserve campaign and hosting context.","Source IDs":"N18","Notes":"Push lists the cluster timeframe as January 2026, with one example domain dated December 2025."},{"Type":"SHA-256","Indicator":"c0df36ccf88d5c8434b13b58f7a55a9715643a126148b9d078a93075d09cad26","Campaign / Provider":"Doko-derived heartbeat panel / UNC6671 and BlackFile cluster","Observed From":"2025-12-01","Observed To / Report Date":"2026-01-31","Reported / Historical ASN":"AS39287","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"client.js phishing-panel artifact","Default Use":"Match file and web-content telemetry; preserve campaign and hosting context.","Source IDs":"N18","Notes":"Push lists the cluster timeframe as January 2026, with one example domain dated December 2025."},{"Type":"SHA-256","Indicator":"d178dc7108fa9344dae28e350e810352e9e874563496dc7876ee628b11b0eabb","Campaign / Provider":"Doko-derived heartbeat panel / UNC6671 and BlackFile cluster","Observed From":"2025-12-01","Observed To / Report Date":"2026-01-31","Reported / Historical ASN":"AS39287","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"client.js phishing-panel artifact","Default Use":"Match file and web-content telemetry; preserve campaign and hosting context.","Source IDs":"N18","Notes":"Push lists the cluster timeframe as January 2026, with one example domain dated December 2025."},{"Type":"SHA-256","Indicator":"e8128b33259f7ea4313c942689ba0ba557f17b1474f2e621c62a5b77674fab86","Campaign / Provider":"Doko-derived heartbeat panel / UNC6671 and BlackFile cluster","Observed From":"2025-12-01","Observed To / Report Date":"2026-01-31","Reported / Historical ASN":"AS39287","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"client.js phishing-panel artifact","Default Use":"Match file and web-content telemetry; preserve campaign and hosting context.","Source IDs":"N18","Notes":"Push lists the cluster timeframe as January 2026, with one example domain dated December 2025."},{"Type":"SHA-256","Indicator":"f574b6e6b3a968cda5f51bec2c090d8eb095fbcfc383314f94bc15676a0d6692","Campaign / Provider":"Doko Panel / UNC6661 and ShinyHunters cluster","Observed From":"2025-11-01","Observed To / Report Date":"2026-04-30","Reported / Historical ASN":"AS201814","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"client.js phishing-panel artifact","Default Use":"Match file and web-content telemetry; preserve campaign and hosting context.","Source IDs":"N18","Notes":"Push lists the cluster timeframe as November 2025 through April 2026."},{"Type":"SHA256","Indicator":"0e81d80b40eaacbf6cb1e817fb1824c30a824af5cb4faca4aa9b03fd506d480f","Campaign / Provider":"Kapibala","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Backdoor","Default Use":"Exact-indicator hunt with campaign and observation-date context; revalidate routing and ownership before blocking.","Source IDs":"N39","Notes":"High"},{"Type":"SHA256","Indicator":"0f6e757e82c4d91df5bd249f775b9970b59dee42cc0dfe40f879d77fc16821c6","Campaign / Provider":"Kapibala","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Backdoor","Default Use":"Exact-indicator hunt with campaign and observation-date context; revalidate routing and ownership before blocking.","Source IDs":"N39","Notes":"High"},{"Type":"SHA256","Indicator":"1f2096ff906915fbf80778f0636446206197351f7e271af97936eeb6f32c179d","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-01-01","Observed To / Report Date":"2026-01-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Malicious attachment archive / virtual disk","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026-01."},{"Type":"SHA256","Indicator":"24b6e36a09eb2acfc2a95478ca685acb7593b1689be6a4a639fe0d222393cfa7","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-07-01","Observed To / Report Date":"2026-07-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Malicious attachment archive / virtual disk","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026-07."},{"Type":"SHA256","Indicator":"2ff2945b13a4cd0e9a65c85af29ea1539e162a516466c0de682dbf9f8a4000b1","Campaign / Provider":"Kapibala","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Backdoor","Default Use":"Exact-indicator hunt with campaign and observation-date context; revalidate routing and ownership before blocking.","Source IDs":"N39","Notes":"High"},{"Type":"SHA256","Indicator":"699e92a9e0edf7835879d5697bc67138c0b137117f459caf1a44df357407cad9","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-06-01","Observed To / Report Date":"2026-06-30","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Malicious attachment archive / virtual disk","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026-06."},{"Type":"SHA256","Indicator":"6f5a2a452a7901323abd21879c6cecccb47c06aeeaccb1b467212f3b11e4b1e7","Campaign / Provider":"Citrix CVE-2026-88771 exploitation","Observed From":"","Observed To / Report Date":"","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Webshell","Default Use":"Exact-indicator hunt with campaign and observation-date context; revalidate routing and ownership before blocking.","Source IDs":"N40","Notes":"High"},{"Type":"SHA256","Indicator":"870ed09a1dcd95f6d962ae82e348770c0843c76c3a6d4d989e3ab8288726e947","Campaign / Provider":"GhostCode","Observed From":"2026-08-01","Observed To / Report Date":"2026-08-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Initial lure HTML","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Late August 2026."},{"Type":"SHA256","Indicator":"9707a8694e954e9ee13e839d6e5905ce626c0837c7c90da6d1025bfbe152866b","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-01-01","Observed To / Report Date":"2026-01-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Malicious attachment archive / virtual disk","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026-01."},{"Type":"SHA256","Indicator":"cd84fca18f5f8b388c1c0f60ce60123b1b650925f43d9a0b6629cb21ccaee729","Campaign / Provider":"GhostCode","Observed From":"2026-08-01","Observed To / Report Date":"2026-08-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Decoy NDA PDF","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N49","Notes":"Source observation scope: Late August 2026."},{"Type":"SHA256","Indicator":"dd98dbc1a55afe6fd0ed2ed53a79c76f6bde15081a0060422185b74eb1799ee4","Campaign / Provider":"Star Blizzard / RedFlick","Observed From":"2026-08-01","Observed To / Report Date":"2026-08-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Malicious attachment archive / virtual disk","Default Use":"Exact-indicator hunt with campaign context; no provider-wide inference.","Source IDs":"N55","Notes":"Source observation scope: 2026-08."},{"Type":"User-Agent","Indicator":"python-requests/2.34.2","Campaign / Provider":"GhostCode","Observed From":"2026-08-01","Observed To / Report Date":"2026-08-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"Post-compromise non-interactive token automation","Default Use":"Hunt after device-code authentication/enrollment; normal automation also uses this UA.","Source IDs":"N48","Notes":"Source observation scope: Late August 2026."},{"Type":"IPv4","Indicator":"104.28.155.27","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-06-19","Observed To / Report Date":"2026-06-20","Reported / Historical ASN":"AS13335","Reported / Historical Prefix":"104.28.155.0/24","Current ASN":"AS13335","Current Prefix":"104.28.155.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN brute force or successful authentication with a compromised account","Default Use":"Time-bounded exact-IP hunt across VPN and firewall authentication logs; revalidate before blocking.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history."},{"Type":"IPv4","Indicator":"185.136.15.43","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-06-27","Observed To / Report Date":"2026-07-23","Reported / Historical ASN":"AS205997","Reported / Historical Prefix":"185.136.15.0/24","Current ASN":"AS210328","Current Prefix":"185.136.15.0/24","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"VPN brute force or successful authentication with a compromised account","Default Use":"Time-bounded exact-IP hunt across VPN and firewall authentication logs; revalidate before blocking.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history."},{"Type":"IPv4","Indicator":"185.136.15.66","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-06-27","Observed To / Report Date":"2026-07-23","Reported / Historical ASN":"AS205997","Reported / Historical Prefix":"185.136.15.0/24","Current ASN":"AS210328","Current Prefix":"185.136.15.0/24","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"VPN brute force or successful authentication with a compromised account","Default Use":"Time-bounded exact-IP hunt across VPN and firewall authentication logs; revalidate before blocking.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history."},{"Type":"IPv4","Indicator":"185.199.199.56","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-06-25","Observed To / Report Date":"2026-06-25","Reported / Historical ASN":"AS212171","Reported / Historical Prefix":"185.199.196.0/22","Current ASN":"AS213929","Current Prefix":"185.199.196.0/22","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"VPN brute force or successful authentication with a compromised account","Default Use":"Time-bounded exact-IP hunt across VPN and firewall authentication logs; revalidate before blocking.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history."},{"Type":"IPv4","Indicator":"193.8.186.33","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-06-18","Observed To / Report Date":"2026-07-20","Reported / Historical ASN":"AS201002","Reported / Historical Prefix":"193.8.186.0/24","Current ASN":"AS201002","Current Prefix":"193.8.186.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN brute force or successful authentication with a compromised account","Default Use":"Time-bounded exact-IP hunt across VPN and firewall authentication logs; revalidate before blocking.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history."},{"Type":"IPv4","Indicator":"45.227.254.210","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-06-18","Observed To / Report Date":"2026-07-23","Reported / Historical ASN":"AS267784","Reported / Historical Prefix":"45.227.254.0/24","Current ASN":"AS267784","Current Prefix":"45.227.254.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN brute force or successful authentication with a compromised account","Default Use":"Time-bounded exact-IP hunt across VPN and firewall authentication logs; revalidate before blocking.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history."},{"Type":"IPv4","Indicator":"77.91.118.10","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-06-18","Observed To / Report Date":"2026-07-05","Reported / Historical ASN":"AS209896","Reported / Historical Prefix":"77.91.118.0/24","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN brute force or successful authentication with a compromised account","Default Use":"Time-bounded exact-IP hunt across VPN and firewall authentication logs; revalidate before blocking.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history. Not currently routed."},{"Type":"IPv4","Indicator":"80.75.212.113","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-06-26","Observed To / Report Date":"2026-07-05","Reported / Historical ASN":"AS49581","Reported / Historical Prefix":"80.75.212.0/24","Current ASN":"AS49581","Current Prefix":"80.75.212.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN brute force or successful authentication with a compromised account","Default Use":"Time-bounded exact-IP hunt across VPN and firewall authentication logs; revalidate before blocking.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history."},{"Type":"IPv4","Indicator":"87.251.64.13","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-06-18","Observed To / Report Date":"2026-07-22","Reported / Historical ASN":"AS200730","Reported / Historical Prefix":"87.251.64.0/24","Current ASN":"AS212835","Current Prefix":"87.251.64.0/24","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"VPN brute force or successful authentication with a compromised account","Default Use":"Time-bounded exact-IP hunt across VPN and firewall authentication logs; revalidate before blocking.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history."},{"Type":"IPv4","Indicator":"87.251.64.16","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-06-18","Observed To / Report Date":"2026-07-20","Reported / Historical ASN":"AS200730","Reported / Historical Prefix":"87.251.64.0/24","Current ASN":"AS212835","Current Prefix":"87.251.64.0/24","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"VPN brute force or successful authentication with a compromised account","Default Use":"Time-bounded exact-IP hunt across VPN and firewall authentication logs; revalidate before blocking.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history."},{"Type":"IPv4","Indicator":"87.251.64.17","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-06-18","Observed To / Report Date":"2026-07-20","Reported / Historical ASN":"AS200730","Reported / Historical Prefix":"87.251.64.0/24","Current ASN":"AS212835","Current Prefix":"87.251.64.0/24","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"VPN brute force or successful authentication with a compromised account","Default Use":"Time-bounded exact-IP hunt across VPN and firewall authentication logs; revalidate before blocking.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history."},{"Type":"IPv4","Indicator":"87.251.64.44","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-07-04","Observed To / Report Date":"2026-07-04","Reported / Historical ASN":"AS200730","Reported / Historical Prefix":"87.251.64.0/24","Current ASN":"AS212835","Current Prefix":"87.251.64.0/24","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"VPN brute force or successful authentication with a compromised account","Default Use":"Time-bounded exact-IP hunt across VPN and firewall authentication logs; revalidate before blocking.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history."},{"Type":"IPv4","Indicator":"66.175.220.111","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-07-17","Observed To / Report Date":"2026-07-19","Reported / Historical ASN":"AS63949","Reported / Historical Prefix":"66.175.216.0/21","Current ASN":"AS63949","Current Prefix":"66.175.216.0/21","Current Country":"","Mapping Changed":"No","Telemetry Context":"VPN brute force or successful authentication with a compromised account","Default Use":"Time-bounded exact-IP hunt across VPN and firewall authentication logs; revalidate before blocking.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history."},{"Type":"IPv4","Indicator":"45.154.12.132","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-06-18","Observed To / Report Date":"2026-10-06","Reported / Historical ASN":"AS138195","Reported / Historical Prefix":"45.154.12.0/24","Current ASN":"AS138195","Current Prefix":"45.154.12.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"C2 server","Default Use":"Exact-IOC retro-hunt; correlate with FortiGate and VPN logs; do not ASN-block.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history. Activity window per advisory, June to July 2026."},{"Type":"IPv4","Indicator":"154.202.59.169","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-06-18","Observed To / Report Date":"2026-10-06","Reported / Historical ASN":"AS40065","Reported / Historical Prefix":"154.202.32.0/19","Current ASN":"AS22516","Current Prefix":"154.202.32.0/19","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Proxy node","Default Use":"Exact-IOC retro-hunt; correlate with FortiGate and VPN logs; do not ASN-block.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history. Activity window per advisory, June to July 2026."},{"Type":"IPv4","Indicator":"103.27.186.156","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-06-18","Observed To / Report Date":"2026-10-06","Reported / Historical ASN":"AS134835","Reported / Historical Prefix":"103.27.186.0/24","Current ASN":"AS134835","Current Prefix":"103.27.186.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Proxy node","Default Use":"Exact-IOC retro-hunt; correlate with FortiGate and VPN logs; do not ASN-block.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history. Activity window per advisory, June to July 2026."},{"Type":"IPv4","Indicator":"45.155.250.158","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-06-18","Observed To / Report Date":"2026-10-06","Reported / Historical ASN":"AS42708","Reported / Historical Prefix":"45.155.250.0/24","Current ASN":"AS42708","Current Prefix":"45.155.250.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Beacon relay","Default Use":"Exact-IOC retro-hunt; correlate with FortiGate and VPN logs; do not ASN-block.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history. Activity window per advisory, June to July 2026."},{"Type":"IPv4","Indicator":"193.8.187.2","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-06-18","Observed To / Report Date":"2026-10-06","Reported / Historical ASN":"AS206378","Reported / Historical Prefix":"193.8.187.0/24","Current ASN":"AS206378","Current Prefix":"193.8.187.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Attack-chain infrastructure","Default Use":"Exact-IOC retro-hunt; correlate with FortiGate and VPN logs; do not ASN-block.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history. Activity window per advisory, June to July 2026."},{"Type":"IPv4","Indicator":"193.8.187.42","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-06-18","Observed To / Report Date":"2026-10-06","Reported / Historical ASN":"AS206378","Reported / Historical Prefix":"193.8.187.0/24","Current ASN":"AS206378","Current Prefix":"193.8.187.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"Attack-chain infrastructure","Default Use":"Exact-IOC retro-hunt; correlate with FortiGate and VPN logs; do not ASN-block.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history. Activity window per advisory, June to July 2026."},{"Type":"IPv4","Indicator":"85.11.187.8","Campaign / Provider":"FortiBleed FortiGate SSL-VPN brute force","Observed From":"2026-06-18","Observed To / Report Date":"2026-10-06","Reported / Historical ASN":"AS211486","Reported / Historical Prefix":"85.11.187.0/24","Current ASN":"AS211443","Current Prefix":"85.11.187.0/24","Current Country":"","Mapping Changed":"Yes","Telemetry Context":"Hashtopolis password cracking","Default Use":"Exact-IOC retro-hunt; correlate with FortiGate and VPN logs; do not ASN-block.","Source IDs":"N62","Notes":"FBI and USSS warn the address may since have been reassigned. ASN from RIPEstat routing history. Activity window per advisory, June to July 2026."},{"Type":"IPv4","Indicator":"213.111.185.108","Campaign / Provider":"INC ransomware","Observed From":"2026-08-01","Observed To / Report Date":"2026-08-31","Reported / Historical ASN":"AS9009","Reported / Historical Prefix":"213.111.185.0/24","Current ASN":"AS9009","Current Prefix":"213.111.185.0/24","Current Country":"","Mapping Changed":"No","Telemetry Context":"AnyDesk C2","Default Use":"Exact-IOC retro-hunt; correlate identity/session or host behavior; do not ASN-block.","Source IDs":"N63","Notes":"Reverse DNS 108.185.111.213.static.edisglobal.com: an EDIS customer VPS, not an AnyDesk relay."},{"Type":"Domain","Indicator":"throughoutes.net","Campaign / Provider":"INC ransomware","Observed From":"2026-08-01","Observed To / Report Date":"2026-08-31","Reported / Historical ASN":"","Reported / Historical Prefix":"","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"Not applicable","Telemetry Context":"C2","Default Use":"Exact-indicator hunt in DNS and proxy logs; verify current resolution.","Source IDs":"N63","Notes":"Contacted by an obfuscated PowerShell implant."},{"Type":"CIDR","Indicator":"2a0a:d683::/32","Campaign / Provider":"LSHIY password spray","Observed From":"2026-06-12","Observed To / Report Date":"2026-06-26","Reported / Historical ASN":"AS32167","Reported / Historical Prefix":"2a0a:d683::/32","Current ASN":"","Current Prefix":"","Current Country":"","Mapping Changed":"No","Telemetry Context":"Entra ID password and token spray source","Default Use":"Historical exact-range hunt in Entra sign-in logs.","Source IDs":"X008","Notes":"Not currently routed. Abusing BYOIP customer suspended by LSHIY on 2026-07-02."},{"Type":"IPv4","Indicator":"162.220.234.41","Campaign / Provider":"EvilTokens device-code phishing","Observed From":"2026-02-19","Observed To / Report Date":"2026-03-23","Reported / Historical ASN":"AS400940","Reported / Historical Prefix":"162.220.234.0/23","Current ASN":"AS400940","Current Prefix":"162.220.234.0/23","Current Country":"","Mapping Changed":"No","Telemetry Context":"Dominant token replay engine","Default Use":"Exact-IP hunt in Entra sign-in logs for device-code and token events.","Source IDs":"N58, N59","Notes":"Railway PaaS. 254 events in Huntress telemetry."}],"provider_families":[{"Provider Family":"kontrast.md","Enabled ASN Count":"34","T1 Count":"34","T2 Count":"0","T3 Count":"0","T4 Count":"2","US ASN Count":"0","Foreign ASN Count":"36","Country Mix":"MD:36","Example ASNs":"AS201813, AS203950, AS204794, AS204868, AS204872, AS205301, AS205745, AS205770, AS205884, AS206005, AS206127, AS206305","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"Unclassified","Enabled ASN Count":"17","T1 Count":"0","T2 Count":"3","T3 Count":"14","T4 Count":"114","US ASN Count":"6","Foreign ASN Count":"124","Country Mix":"BR:33, RU:17, MD:13, UA:12, MX:7, US:6, AR:5, IN:5, GB:3, AL:2, AM:2, CO:2, DE:2, HK:2, ID:2, TR:2, VE:2, AE:1, AT:1, DO:1, EC:1, ES:1, GT:1, IQ:1, IR:1, KE:1, LB:1, RO:1, UZ:1, ZA:1, ZZ:1","Example ASNs":"AS14956, AS48282, AS215238, AS9009, AS11938, AS26496, AS26701, AS35346, AS40403, AS45753, AS48031, AS58349","Source IDs":"N01, S02, S03, S05, S08, X001, X002, X004, X005, X006, X007, X009, X010, X011, X012, X015, X016, X017, X018, X022, X027, X029, X033, X039, X041, X042, X043, X044, X051, X052, X059, X060, X061, X062, X063, X064, X068, X069","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"bignet.ua","Enabled ASN Count":"14","T1 Count":"14","T2 Count":"0","T3 Count":"0","T4 Count":"3","US ASN Count":"0","Foreign ASN Count":"17","Country Mix":"UA:11, NL:6","Example ASNs":"AS6729, AS9164, AS25288, AS38946, AS42505, AS43668, AS43743, AS47893, AS47926, AS47945, AS51124, AS57415","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"cloudie.hk","Enabled ASN Count":"9","T1 Count":"9","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"8","Country Mix":"HK:8, US:1","Example ASNs":"AS24544, AS25862, AS38871, AS55933, AS133731, AS134176, AS134196, AS154206, AS208525","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"pitline.net","Enabled ASN Count":"9","T1 Count":"9","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"9","Country Mix":"UA:6, CH:1, FR:1, RU:1","Example ASNs":"AS2601, AS31561, AS43481, AS51511, AS56362, AS57100, AS62206, AS208241, AS215765","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"ipswat.com","Enabled ASN Count":"6","T1 Count":"6","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"6","Foreign ASN Count":"0","Country Mix":"US:6","Example ASNs":"AS3507, AS394082, AS397881, AS400177, AS400522, AS402647","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"serverion.com","Enabled ASN Count":"6","T1 Count":"6","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"2","Foreign ASN Count":"4","Country Mix":"NL:4, US:2","Example ASNs":"AS56584, AS210654, AS213035, AS213753, AS399471, AS400377","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"bunnycommunications.com","Enabled ASN Count":"5","T1 Count":"5","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"4","Foreign ASN Count":"1","Country Mix":"US:4, JP:1","Example ASNs":"AS5065, AS6207, AS39600, AS142622, AS399073","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"fineproxy.org","Enabled ASN Count":"5","T1 Count":"5","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"5","Country Mix":"ZA:3, IL:1, RU:1","Example ASNs":"AS35624, AS35830, AS43444, AS59651, AS211762","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"PacketHub","Enabled ASN Count":"5","T1 Count":"0","T2 Count":"5","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"5","Country Mix":"PA:4, AU:1","Example ASNs":"AS136787, AS141039, AS147049, AS207137, AS272096","Source IDs":"N01, N15, N16, N29, N30, N31","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"62yun.com","Enabled ASN Count":"4","T1 Count":"4","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"3","Foreign ASN Count":"2","Country Mix":"US:3, KG:1, NG:1","Example ASNs":"AS60842, AS215340, AS398741, AS400992, AS50236","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"bunea.eu","Enabled ASN Count":"4","T1 Count":"4","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"4","Country Mix":"RO:3, GB:1","Example ASNs":"AS35478, AS42397, AS47890, AS62380","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"centralnic.com","Enabled ASN Count":"4","T1 Count":"0","T2 Count":"4","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"4","Country Mix":"GB:4","Example ASNs":"AS60890, AS199330, AS201303, AS201304","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"globaltelehost.com","Enabled ASN Count":"4","T1 Count":"0","T2 Count":"0","T3 Count":"4","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"4","Country Mix":"CA:4, US:1","Example ASNs":"AS20724, AS61003, AS62563, AS63023, AS27463","Source IDs":"N01, N42, S01, S02","Recommended Handling":"Use as a sign-in risk multiplier with device, MFA, session, event-country, or post-authentication anomalies. Do not treat delisting as safety."},{"Provider Family":"lordvps.net","Enabled ASN Count":"4","T1 Count":"4","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"4","Country Mix":"IR:3, ZA:1","Example ASNs":"AS48214, AS52209, AS58192, AS209425","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"netinnovation.net","Enabled ASN Count":"4","T1 Count":"4","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"4","Foreign ASN Count":"0","Country Mix":"US:4","Example ASNs":"AS23865, AS34985, AS62864, AS149286","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"almaseabi.net","Enabled ASN Count":"3","T1 Count":"3","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"3","Country Mix":"GB:1, IR:1, RS:1","Example ASNs":"AS210703, AS214357, AS215930","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"alphainfolab.com","Enabled ASN Count":"3","T1 Count":"3","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"2","Foreign ASN Count":"1","Country Mix":"US:2, IN:1","Example ASNs":"AS132574, AS133320, AS400171","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"chosting.solutions","Enabled ASN Count":"3","T1 Count":"3","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"3","Country Mix":"GB:3","Example ASNs":"AS49418, AS198981, AS210546","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"eksenbilisim.com.tr","Enabled ASN Count":"3","T1 Count":"3","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"3","Country Mix":"TR:3","Example ASNs":"AS208198, AS210714, AS212666","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"ipconnect.services","Enabled ASN Count":"3","T1 Count":"3","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"3","Country Mix":"SC:3","Example ASNs":"AS210530, AS211922, AS213373","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"ithostline.com","Enabled ASN Count":"3","T1 Count":"3","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"3","Country Mix":"IN:2, CY:1","Example ASNs":"AS44559, AS150101, AS150102","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"net-gate.ro","Enabled ASN Count":"3","T1 Count":"3","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"3","Country Mix":"RO:3","Example ASNs":"AS34450, AS208185, AS216378","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"netiface.co.uk","Enabled ASN Count":"3","T1 Count":"3","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"2","Foreign ASN Count":"1","Country Mix":"US:2, GB:1","Example ASNs":"AS33042, AS203861, AS401626","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"qwins.co","Enabled ASN Count":"3","T1 Count":"3","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"3","Country Mix":"GB:1, LV:1, UA:1","Example ASNs":"AS213702, AS214422, AS218731","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"rapidoserver.com","Enabled ASN Count":"3","T1 Count":"3","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"3","Country Mix":"IR:3","Example ASNs":"AS198926, AS210705, AS218732","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"ryzehosting.com","Enabled ASN Count":"3","T1 Count":"3","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"3","Country Mix":"AT:3","Example ASNs":"AS200130, AS211066, AS215136","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"sunucun.com.tr","Enabled ASN Count":"3","T1 Count":"3","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"3","Country Mix":"TR:2, BR:1","Example ASNs":"AS197450, AS205486, AS213652","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"xor.sc","Enabled ASN Count":"3","T1 Count":"3","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"3","Country Mix":"SC:3","Example ASNs":"AS200699, AS205083, AS211720","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"Aeza Group","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"RU:2","Example ASNs":"AS210644, AS216246","Source IDs":"N01, S01, S02, S03, S09, S14","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"Bearhost-linked","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"GB:1, RU:1","Example ASNs":"AS201738, AS211663","Source IDs":"N01, S01, S02, S03, X072","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"berdiev-ruslan-mukhabatovich","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"RU:2","Example ASNs":"AS214576, AS215402","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"changway.hk","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"HK:2","Example ASNs":"AS59425, AS207566","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"cognetcloud.com","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"2","Foreign ASN Count":"0","Country Mix":"US:2","Example ASNs":"AS401696, AS401701","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"ddps.jp","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"JP:2","Example ASNs":"AS18526, AS26132","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"dedik.io","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"GB:2","Example ASNs":"AS207043, AS209413","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"ekoiniciative.pp.ua","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"UA:2","Example ASNs":"AS201572, AS202318","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"FIRST SERVER","Enabled ASN Count":"2","T1 Count":"0","T2 Count":"0","T3 Count":"2","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"GB:2","Example ASNs":"AS204997, AS205090","Source IDs":"N01, N19, N22","Recommended Handling":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies."},{"Provider Family":"Flyservers","Enabled ASN Count":"3","T1 Count":"0","T2 Count":"2","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"3","Country Mix":"PA:3","Example ASNs":"AS48721, AS209588","Source IDs":"N01, X057","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"globtelgroup.com","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"2","Foreign ASN Count":"0","Country Mix":"US:2","Example ASNs":"AS135271, AS203120","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"hosterdaddy.com","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"IN:2","Example ASNs":"AS152485, AS215117","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"imtigernet","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"GB:2","Example ASNs":"AS48589, AS211121","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"itsidc.com","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"HK:1, JP:1","Example ASNs":"AS134121, AS138968","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"kaopuyun.com","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"CN:1, HK:1","Example ASNs":"AS58854, AS154177","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"kyonix.com","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"GB:1, ID:1","Example ASNs":"AS200051, AS210457","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"liptel.net.ua","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"3","Country Mix":"UA:3","Example ASNs":"AS209121, AS211199, AS43613","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"ozon.ru","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"RU:2","Example ASNs":"AS44386, AS207986","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"pfcloud.io","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"DE:1, NL:1","Example ASNs":"AS215310, AS400328","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"serveroffer.lt","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"HK:1, LT:1","Example ASNs":"AS135388, AS209605","Source IDs":"N01, S01, S02, S03, S05, X067","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"seyix.sc","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"SC:2","Example ASNs":"AS37707, AS327837","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"snowcore.io","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"1","Country Mix":"DE:1, US:1","Example ASNs":"AS216078, AS218986","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"Stark / PQ.Hosting / THE.Hosting / UFO","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"NL:1, RU:1","Example ASNs":"AS33993, AS209847","Source IDs":"N01, S01, S02, S03, S05, S12, S13","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"Strong Technology / NetProtect","Enabled ASN Count":"2","T1 Count":"0","T2 Count":"0","T3 Count":"2","T4 Count":"3","US ASN Count":"5","Foreign ASN Count":"0","Country Mix":"US:5","Example ASNs":"AS54203, AS62651, AS13926, AS22781, AS140952","Source IDs":"N01, N35, N36","Recommended Handling":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies."},{"Provider Family":"swissnetwork.io","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"1","Country Mix":"IR:1, US:1","Example ASNs":"AS199467, AS209373","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"trafficforce.lt","Enabled ASN Count":"2","T1 Count":"0","T2 Count":"0","T3 Count":"2","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"LT:2","Example ASNs":"AS133944, AS202496","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"tube-hosting.de","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"DE:2","Example ASNs":"AS49581, AS213200","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"zerolimit-servers.cool","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"MD:1, UA:1","Example ASNs":"AS205997, AS206378","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"123host.vn","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"VN:1","Example ASNs":"AS56153","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"1GSERVERS","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS14315","Source IDs":"N01, N06","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"3xK Tech / Plain Proxies","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS200373","Source IDs":"N01, S01, S02, S03, S05, X008","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"69host.cc","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS205397","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"acerdp.io","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS206479","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"adoard.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS207088","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"advinservers.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS22295","Source IDs":"N01, S02, S03, S05, X019, X020","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"aeza.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"EE:1","Example ASNs":"AS203273","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"agotoz.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"SG:1","Example ASNs":"AS9465","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"agrofirma-aleks","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS201292","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"ahamed.com.bd","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS152149","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"Akamai Connected Cloud","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"SG:1","Example ASNs":"AS63949","Source IDs":"N01","Recommended Handling":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies."},{"Provider Family":"akronic.network","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS199829","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"aleducacional.com.br","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS61879","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"algoz.co.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS150030","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"altawk.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS209946","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"ananyacomp.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS149242","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"apexstrata.ie","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IE:1","Example ASNs":"AS214973","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"arkcomtele.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS150100","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"AS-493NETWORKING","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS399979","Source IDs":"N01, S01, S02, S03, X071","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"AS-COLOCROSSING","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS36352","Source IDs":"N01, N06","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"as210558.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS210558","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"as215764.net","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ES:1","Example ASNs":"AS215764","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"AS62904","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS62904","Source IDs":"N01, N06","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"astelon.net","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CH:1","Example ASNs":"AS203718","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"atom3.com.ua","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS208846","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"auproxies.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS53958","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"avtotrans","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS48198","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"bakrietelecom.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ID:1","Example ASNs":"AS38149","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"barebox.com.bd","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS147034","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"bbhost.com.br","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS265919","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"berch.co.uk","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS198071","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"bhagwatsoft.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS149181","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"bhs.solutions","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS216067","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"biil.ru","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS215474","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"biterika.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS35048","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"bizimbulut.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS203979","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"bkns.vn","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"VN:1","Example ASNs":"AS135967","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"blackappleus.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS400506","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"blatant.host","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"SC:1","Example ASNs":"AS403005","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate identity, device, session, event-country, and post-authentication activity; review dependencies before deny actions."},{"Provider Family":"BLNWX","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS399629","Source IDs":"N01, N09","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"blueberrywebs.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS137156","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"bluecentrix.co.za","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ZA:1","Example ASNs":"AS328819","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"bluegate-exchange.co.za","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ZA:1","Example ASNs":"AS328095","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"BlueVPS","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"EE:1","Example ASNs":"AS62005","Source IDs":"N01, N06, N08","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"brutalproxies.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS212867","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"bst.lt","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS43463","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"btcloud.ro","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS213790","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"bubblesalter","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS213897","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"caiwireless.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS8129","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"cantech.international","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS200010","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"capitalonline.net","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"HK:1","Example ASNs":"AS154701","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"CDNEXT Datacamp Limited","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS212238","Source IDs":"N01, N09","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"cheapy.host","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS401120","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"chempir","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS202144","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"CHIARA-AS","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IT:1","Example ASNs":"AS219067","Source IDs":"N01, S01, S02, S03, X074","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"cloudbs.biz","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BG:1","Example ASNs":"AS57509","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"cloudfly.vn","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"VN:1","Example ASNs":"AS149089","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"cloudsp-lb.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"LB:1","Example ASNs":"AS57852","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"Clouvider","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"9","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"10","Country Mix":"GB:10","Example ASNs":"AS62240, AS34202, AS43878, AS202791, AS202792, AS206136, AS206822, AS206848, AS207019, AS207158","Source IDs":"N01, N06, N07, N08, N09, N10, N11, N12, N13, N14, N16, N34, S04, S06","Recommended Handling":"Immediate triage for successful interactive employee sign-ins. Correlate new device, MFA or passkey changes, token behavior, VPN access, session anomalies, and post-authentication activity before containment."},{"Provider Family":"club-nadiya","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS202388","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"code200.global","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"LT:1","Example ASNs":"AS205964","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"colocatel.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"SC:1","Example ASNs":"AS213438","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"Contabo","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS51167","Source IDs":"N01","Recommended Handling":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies."},{"Provider Family":"contell.ru","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS204490","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"crazetechnology.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS133244","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"ctgserver.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"HK:1","Example ASNs":"AS152194","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"cubilloconstrucciones.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ES:1","Example ASNs":"AS212017","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"cyberauticssoftwares.co.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS140125","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"cyberdatanetworks.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS400882","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"cybrscrb.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"SC:1","Example ASNs":"AS328958","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"d-conect","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS212651","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"dadeh-pardazesh-boroumand-kerman","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IR:1","Example ASNs":"AS210707","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"datahome.com.tr","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS213945","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"datahost.com.tr","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS60647","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"dataparadise.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS147287","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"datawingstel.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS147269","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"davidascottmotorsltd","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS213921","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"dehost.com.tr","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS47516","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"dhost.su","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS209207","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"digital-snap.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS150055","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"DigitalOcean","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS14061","Source IDs":"N01, N06, N09","Recommended Handling":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies."},{"Provider Family":"digivps.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS142430","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"dm-auto.eu","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BG:1","Example ASNs":"AS207812","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"dmzhost.co","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS48090","Source IDs":"N01, S01, S02, S03, S05, X045","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"dobrosvitkredo","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS202267","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"domainhizmetleri.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS34828","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"donserver.cl","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CL:1","Example ASNs":"AS266724","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"dpc24.ru","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS208981","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"ecxon.com.br","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS270764","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"eikontech.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS133668","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"ekiphost.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS209474","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"el-k-stil","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS202383","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"elekoms.net.ua","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS210316","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"elende.ao","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AO:1","Example ASNs":"AS329007","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"empire-communications","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS7857","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"enterprises-holding","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS200499","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"erishennya","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS210950","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"estoxy.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"EE:1","Example ASNs":"AS61254","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"evokedigital.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS135752","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"EVOXTSDNBHD-AS-AP","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"MY:1","Example ASNs":"AS149440","Source IDs":"N01, N09","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"excitedmatch.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS201380","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"farahoosh.ir","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IR:1","Example ASNs":"AS44208","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"fastnetcpl.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS133692","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"Femo IT Solutions","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS214351","Source IDs":"N01, S01, S02, S03, S05, X003, X031","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"feoprest.info","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RO:1","Example ASNs":"AS208137","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"fibacloud.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS44382","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"FlokiNET","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IS:1","Example ASNs":"AS200651","Source IDs":"N01, N19","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"flowerproxy.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IL:1","Example ASNs":"AS202226","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"fly-group.ru","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS199420","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"FranTech / BuyVM","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS53667","Source IDs":"N01, S02, S03, S05, X008","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"FREAKHOSTING FREAKHOSTING LTD","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS215703","Source IDs":"N01, N06","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"frostyhosting","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS213995","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"fulltimehosting.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PK:1","Example ASNs":"AS140941","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"g-w.bz","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"JP:1","Example ASNs":"AS132827","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"garant-plus-inform","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS201836","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"geniusweer.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"FR:1","Example ASNs":"AS214154","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"getechbrothers.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"LT:1","Example ASNs":"AS202044","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"girdharicomp.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS149197","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"globalsol.co.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS150604","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"globaltransitsystems.online","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS213954","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"gmtech.com.bd","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS152192","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"grandwebsolutions.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS46370","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"greencloudvps.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"VN:1","Example ASNs":"AS63734","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"greenhost.net","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"NL:1","Example ASNs":"AS152460","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"gwhostinglabs.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS203999","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"h2.nexus","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AE:1","Example ASNs":"AS215730","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"hayashimo.net","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS399935","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"heebshealthcare.co.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS150036","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"herbalvedawellness.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS132930","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"herbzoothealthcare.co.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS136367","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"Hetzner","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS24940","Source IDs":"N01","Recommended Handling":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies."},{"Provider Family":"hnhosting.net","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"HN:1","Example ASNs":"AS266842","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"hornet.pl","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS34254","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"hostglobal.plus","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS202306","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"HOSTHATCH","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS63473","Source IDs":"N01, N06","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"hostifox.com.tr","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS205733","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"hostlab.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS207326","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"HostRoyale","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS203020","Source IDs":"N01, N08","Recommended Handling":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies."},{"Provider Family":"HostSailor","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AE:1","Example ASNs":"AS60117","Source IDs":"N01, X057","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"hostslick.de","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"SC:1","Example ASNs":"AS197170","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"hts.vn","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"VN:1","Example ASNs":"AS131388","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"HVC-AS","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS29802","Source IDs":"N01, N06, N07","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"Hydra Communications","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS25369","Source IDs":"N01, N17","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"hyehost.org","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS47272","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"hyperion.cloud","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"FR:1","Example ASNs":"AS216193","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"hypernex.cc","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS200912","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"HZ-EU-AS HZ Hosting Ltd","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BG:1","Example ASNs":"AS59711","Source IDs":"N01, N07","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"HZ-US-AS HZ Hosting Ltd","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BG:1","Example ASNs":"AS202015","Source IDs":"N01, N06, N07","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"ib.systems","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS41745","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"iic-rail","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS213388","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"imaginetechnosoft.co.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS141836","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"imasfs.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CY:1","Example ASNs":"AS204610","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"impactsoftwares.co.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS141835","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"infiniroute.io","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IL:1","Example ASNs":"AS215460","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"INOVARE-AS Inovare-Prim SRL","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"MD:1","Example ASNs":"AS60602","Source IDs":"N01, N06","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"inoxweb.com.tr","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS213488","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"intechmandiri.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ID:1","Example ASNs":"AS138808","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"interspireaddon.co.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS141567","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"intintell.co.uk","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS214018","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"invisionchiptechnosoft.co.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS141803","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"IONOS","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS8560","Source IDs":"N01","Recommended Handling":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies."},{"Provider Family":"iprowireless.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AL:1","Example ASNs":"AS201249","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"ipv4holdings.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS400641","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"ipv4superhub.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"HK:2","Example ASNs":"AS209178, AS219181","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"ipvolume.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"SC:1","Example ASNs":"AS202425","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"isofttechnology.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS150082","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"IWEB-AS","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CA:1","Example ASNs":"AS32613","Source IDs":"N01, N07","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"ixirhost.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS206991","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"jdmbroadband.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS152486","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"jellydigital.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS398638","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"jetcloud.vn","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"VN:1","Example ASNs":"AS150860","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"jmvtechnology.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS271437","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"KAOPU-HK","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"HK:1","Example ASNs":"AS138915","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"khalidgroup.co","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PK:1","Example ASNs":"AS147291","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"king-servers.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS14576","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"klikindonesia.or.id","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ID:1","Example ASNs":"AS58961","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"kyliecdn","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CN:1","Example ASNs":"AS197176","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"LATITUDE-SH","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS396356","Source IDs":"N01, N06","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"LEASEWEB-USA-WDC","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS30633","Source IDs":"N01, N06","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"lexistream.net","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"SC:1","Example ASNs":"AS329225","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"lhwebtech.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS54497","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"liasail.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"HK:1","Example ASNs":"AS17497","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"link-host.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS61432","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"livecomm","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS212622","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"livela","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS204502","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"mabasafenet.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS140129","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"macrogate.net","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS202124","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"madgenius.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS55154","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"mathost.eu","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS214762","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"Media Land / ML Cloud","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS206728","Source IDs":"N01, S01, S02, S03, S11, S20","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"medianetdigital.co","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ID:1","Example ASNs":"AS63881","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"MEVSPACE","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS201814","Source IDs":"N01, N17, N18, N21","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"mgcloud.com.br","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS268433","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"miriquidi-networks.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS20292","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"mortalsoft.online","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS209274","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"mullcloud.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS397006","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"mxfiber.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS13875","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"my.papiliohost.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IR:1","Example ASNs":"AS207350","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"mylir.co.uk","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"2","Foreign ASN Count":"0","Country Mix":"US:2","Example ASNs":"AS6186, AS26561","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"net-host.org","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"KZ:1","Example ASNs":"AS216473","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"Netiface","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS36680","Source IDs":"N01, S01, S02, S03, X073","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"netip.com.ua","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS213389","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"netscout.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS20052","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"NEXEON-AS-AP","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS131199","Source IDs":"N01, N06","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"nexon.co.kr","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"KR:1","Example ASNs":"AS131831","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"nextdns.io","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS34939","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"Njalla","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RO:1","Example ASNs":"AS39287","Source IDs":"N01, N18, N21","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"nktele.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS216475","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"nodonorte.net.ar","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AR:1","Example ASNs":"AS266702","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"noobtech.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS146887","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"noorhost.com.bd","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS141738","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"notbad.cloud","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS211955","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"novuslabslimited.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS215731","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"novx-systems","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS2702","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"ntel.com.ng","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"NG:1","Example ASNs":"AS327952","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"nts.center","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS210240","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"ntup.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS48693","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"nuxt.cloud","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS216127","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"nybula.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS401116","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"obhost.org","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PK:1","Example ASNs":"AS140208","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"oneman.me","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS212890","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"onlinepragathi.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS147211","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"orbittelekom.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS41155","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"ORG-LVA15-AS HOSTKEY B.V.","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"NL:1","Example ASNs":"AS50867","Source IDs":"N01, N09","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"ozkula.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS211859","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"PFCLOUD","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS51396","Source IDs":"N01, S01, S02, S03, S05, X053, X054, X076","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"phost.kz","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"KZ:1","Example ASNs":"AS212835","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"pilot.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS3563","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"pixoof.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS51722","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"plainproxies.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS198571","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"planningresearchcorp.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS245","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"Private Layer","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PA:1","Example ASNs":"AS51852","Source IDs":"N01, N17","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"pro-spero.ru","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS200593","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"proton66.ru","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS198953","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"psb.hosting","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS214927","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"purevoltage.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS26548","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"qlhost.cc","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TW:1","Example ASNs":"AS142062","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"qrator.net","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CZ:1","Example ASNs":"AS209671","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"quarterhill.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS26833","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"racksphere.io","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PA:1","Example ASNs":"AS64107","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"rasuhost.com.bd","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS152327","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"reapolis","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS202481","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"REG.RU","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS197695","Source IDs":"N01, S07, S08","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"regxa.iq","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IQ:1","Example ASNs":"AS215311","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"RELIABLESITE","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS23470","Source IDs":"N01, N06","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"render.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS397273","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"rinnai.co.kr","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"KR:1","Example ASNs":"AS17612","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"rmhospitality.co.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS133994","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"robustedge.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS138749","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"rocketmediagroups.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS141333","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"rootlayer.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS51447","Source IDs":"N01, S01, S02, S03, S05, X055","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"rosa-holidays.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BG:1","Example ASNs":"AS212283","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"RUTIL-BG-AS Rutil Ltd.","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BG:1","Example ASNs":"AS21249","Source IDs":"N01, N06","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"s-host.com.ua","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS202302","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"sabotage.net","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS61125","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"sajibhost.com.bd","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS152170","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"sakuraclouds.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS214478","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"sby-telecom.info","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS206791","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"SCALAXY-AS Scalaxy B.V.","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"LV:1","Example ASNs":"AS58061","Source IDs":"N01, N38","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"Scaleway","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"FR:1","Example ASNs":"AS12876","Source IDs":"N01","Recommended Handling":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies."},{"Provider Family":"scloud.sg","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"SG:1","Example ASNs":"AS142002","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"seacom.cc","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS400018","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"seasoncloud.com.br","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS210940","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"securecommsgroup.xyz","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS402075","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"seroweb.xyz","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS402186","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"serv.host","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS207957","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"server-panel.org","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"SC:1","Example ASNs":"AS210848","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"ServerMania / B2 Net Solutions","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CA:1","Example ASNs":"AS55286","Source IDs":"N01, S04, S06","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"servervia.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS203771","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"servicehk.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"HK:1","Example ASNs":"AS133488","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"sfns","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS140184","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"shereverov.marat","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"KZ:1","Example ASNs":"AS210006","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"SHOCK-1","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS395092","Source IDs":"N01","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"skntelecom.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"KN:1","Example ASNs":"AS402253","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"skypass.tech","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS202520","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"slayergroup.ltd","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS213441","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"smart-host.com.tr","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS198120","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"smartmieten.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS197555","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"smtpmailers.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS142519","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"snthostings.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS140947","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"Sollutium-NL SOLLUTIUM EU Sp z.o.o.","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS43641","Source IDs":"N01, N07","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"sovy.cloud","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS401110","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"SPLICE-AS-AP","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AU:1","Example ASNs":"AS8100","Source IDs":"N01, N06","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"spnhost.com.bd","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS149978","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"srjnhospitality.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS141853","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"sshvps.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS215376","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"ssnet.eu","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BG:1","Example ASNs":"AS204428","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"start-building","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS200671","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"stat-cons","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS201824","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"stealthvm.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS198189","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"stormindustries.llc","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS219502","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"sufia.tv","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ID:1","Example ASNs":"AS131750","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"sulavi.co.uk","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS219326","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"svint.net","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ES:1","Example ASNs":"AS200509","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"syn.one","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS64080","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"tcpshield.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CA:1","Example ASNs":"AS64199","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"teknodc.net","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS199724","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"teknosos.com.tr","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS204491","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"telepatiya.kz","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"KZ:1","Example ASNs":"AS203044","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"telerakesh.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS149208","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"thepinnaclegroup.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS140155","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"thestack.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CN:1","Example ASNs":"AS136923","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"thoimmo.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"VN:1","Example ASNs":"AS150813","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"ticom.net","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS20709","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"time-host.net","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS212913","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"tnddesk.com","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS395898","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"torero","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS202171","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"trit.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS40193","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"turingserver.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"NZ:1","Example ASNs":"AS140869","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"turkbil.com.tr","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS212448","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"tzulo","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS11878","Source IDs":"N01, N17","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"UCloud","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"HK:1","Example ASNs":"AS135377","Source IDs":"N01","Recommended Handling":"Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies."},{"Provider Family":"unesty.net","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS211301","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"UNREAL-SERVERS","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS64236","Source IDs":"N01, N06, N07","Recommended Handling":"Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment."},{"Provider Family":"usips.org","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS397702","Source IDs":"N01, S02, S03","Recommended Handling":"High-severity alert on successful interactive sign-in or failed-to-success sequence. Require prompt identity and endpoint validation."},{"Provider Family":"valkyrie-hosting.net","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS397081","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"vaultdweller.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"EE:1, KZ:1","Example ASNs":"AS215183, AS47105","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"vedimantra.co.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS150091","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"vietserver.vn","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"VN:1","Example ASNs":"AS63737","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"vinahost.vn","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"VN:1","Example ASNs":"AS140787","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"vip-net.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS59683","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"Virtualine","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"SC:1","Example ASNs":"AS202412","Source IDs":"N01, S01, S02, S03, X075","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"volumedrive.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS46664","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"vpsdedic.ru","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS211860","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"vpsdedicated.net","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS197769","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"vpsvault.host","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS215925","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"vsys.host","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS30860","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"Vultr","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS20473","Source IDs":"N01, N06, N07, N09, S08","Recommended Handling":"Use as context for interactive sign-ins, VPN authentication, and management traffic. Require exact IOC or behavioral corroboration because Vultr is a broad multi-tenant cloud."},{"Provider Family":"webwiresolutions.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PK:1","Example ASNs":"AS151604","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"whitelabel.sh","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IL:1, ZZ:1","Example ASNs":"AS214497, AS213474","Source IDs":"N01, S01, S02, S03, S05, X004","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"wirelesscuracao.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CW:1","Example ASNs":"AS26173","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"xdeer.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"HK:1","Example ASNs":"AS138687","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"xproxies.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS11527","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"zaifcomp.in","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS149196","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"zen4softsolution","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS141875","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"zerospace.cloud","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"NL:1","Example ASNs":"AS201801","Source IDs":"N01, S02, S03","Recommended Handling":"Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change."},{"Provider Family":"zexotek.de","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS8649","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"zhongguancun.asia","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS401109","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"zillionnetwork.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS54801","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"zumy.eu","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"SC:1","Example ASNs":"AS211238","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"159.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS49755","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"1aeo.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS36849","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"31173.se","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"SE:1","Example ASNs":"AS49399","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"4830.org","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS206813","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"71036.kz","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"KZ:1","Example ASNs":"AS61367","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"777network.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS149561","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"7startelecom.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PK:1","Example ASNs":"AS141347","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"a2z.az","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AZ:1","Example ASNs":"AS211995","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"abaks.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS41297","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"abitaveraswireless.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DO:1","Example ASNs":"AS274129","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"abuse-manager.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"FR:1","Example ASNs":"AS214961","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"access52.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS208314","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ace-idc.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"JP:1","Example ASNs":"AS56291","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"acebrowse.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS136319","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"acn.group","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS208803","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"aircomm.it","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IT:1","Example ASNs":"AS196865","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ajcomputacion.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"EC:1","Example ASNs":"AS274252","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"Akamai","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"2","US ASN Count":"1","Foreign ASN Count":"1","Country Mix":"NL:1, US:1","Example ASNs":"AS16625, AS20940","Source IDs":"N01","Recommended Handling":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review."},{"Provider Family":"akenai.team","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS219064","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"alfa.net.py","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PY:1","Example ASNs":"AS269930","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"Alibaba Cloud","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CN:1","Example ASNs":"AS45102","Source IDs":"N01","Recommended Handling":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review."},{"Provider Family":"aljeel.ly","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"LY:1","Example ASNs":"AS329130","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"alphastrike.io","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"3","US ASN Count":"0","Foreign ASN Count":"3","Country Mix":"DE:3","Example ASNs":"AS42969, AS208843, AS215778","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"Amazon Web Services","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"2","US ASN Count":"2","Foreign ASN Count":"0","Country Mix":"US:2","Example ASNs":"AS14618, AS16509","Source IDs":"N01","Recommended Handling":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review."},{"Provider Family":"aogarant.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS51488","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"apjii.or.id","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"8","US ASN Count":"0","Foreign ASN Count":"8","Country Mix":"IN:5, VN:3","Example ASNs":"AS132934, AS135850, AS135981, AS136676, AS139549, AS150884, AS151148, AS153016","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"aponit.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS132438","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"appliedprivacy.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AT:1","Example ASNs":"AS208323","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"appserv.co.nz","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"NZ:1","Example ASNs":"AS17994","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"arenaconnect.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS269279","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"artcom.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS33923","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"arte-fact.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS39297","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"as215288.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IT:1","Example ASNs":"AS215288","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"as49870.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PS:1","Example ASNs":"AS47154","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"astra.in.ua","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS207475","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"athena-heberg.fr","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"FR:1","Example ASNs":"AS215813","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"atlanticatelecom.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS272741","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"aurorix.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS214309","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"avanet.net.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS205146","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"aysatecsas.com.co","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CO:1","Example ASNs":"AS272990","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ayshait.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS138992","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"babbar.tech","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"FR:1","Example ASNs":"AS210743","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"banatsync.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RO:1","Example ASNs":"AS198364","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling."},{"Provider Family":"base-net.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS47397","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"baykonur.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS208752","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"bdos.info","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS153307","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"beskidmedia.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS50467","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"bessersolutions.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"VE:1","Example ASNs":"AS272102","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"bigcommerce.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS399566","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"bitnetinternet.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS269546","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"bitsight.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PT:1","Example ASNs":"AS211680","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"bn.by","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BY:1","Example ASNs":"AS31345","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"bogahost.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS199929","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"bouncezero.io","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS198075","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"brnchost.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS214803","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"bsh.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS47860","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"canalsnet.com.ar","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AR:1","Example ASNs":"AS265879","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"celcom.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS198418","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"censys.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"3","US ASN Count":"3","Foreign ASN Count":"0","Country Mix":"US:3","Example ASNs":"AS398324, AS398705, AS398722","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"cenuta.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS213252","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"cetech.net.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS268876","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"Chang Way Technologies","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"HK:1","Example ASNs":"AS57523","Source IDs":"N01, S01, S02, S03, S05, X057","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"chunkserve.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS214481","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"citraberdikari.co.id","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ID:1","Example ASNs":"AS139381","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"climaxnet.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS198525","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"Cloudflare","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS13335","Source IDs":"N01, N20","Recommended Handling":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review."},{"Provider Family":"cloudview.com.bd","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS154676","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"combahton GmbH","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS30823","Source IDs":"N01, S05, X003, X031","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"comfortel.pro","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS213461","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"compusinformatica.com.ar","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AR:1","Example ASNs":"AS265772","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"computermate.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS138183","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"conet.com.ve","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"VE:1","Example ASNs":"AS274202","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"connectlinksp.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS269663","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"connectx.pk","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PK:1","Example ASNs":"AS140210","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"connetsrl.com.ar","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AR:1","Example ASNs":"AS273922","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"corevance.org","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS219335","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ctsolusindo.co.id","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ID:1","Example ASNs":"AS149878","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"cyberology.nl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"NL:1","Example ASNs":"AS215125","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"cyberuno.com.ar","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AR:1","Example ASNs":"AS274898","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"d-kiros.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS61748","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"daginfonet.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS209219","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"darkclub.com.ua","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS39720","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"databridge.international","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS200203","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"datafex.com.tr","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS211560","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"datahub.vn","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"VN:1","Example ASNs":"AS132206","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"datalink.com.bd","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS153490","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"datalix.de","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS58087","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"DDoS-Guard","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS57724","Source IDs":"N01, N17","Recommended Handling":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review."},{"Provider Family":"delta-telecom.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS269357","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"derkom.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS197697","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"detelnetworks.id","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ID:1","Example ASNs":"AS58401","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"dieffeitalia.it","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IT:1","Example ASNs":"AS210238","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"dldservicio.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DO:1","Example ASNs":"AS272149","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"dominion.ru.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS196629","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"driftnet.io","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS211298","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"eagleredes.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS264280","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ELITETEAM / 1337TEAM","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"2","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"SC:2","Example ASNs":"AS51381, AS56873","Source IDs":"N01, S01, S02, S03, S05, S16","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"elmamultimedia.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS149638","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"elsuhdnet.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IQ:1","Example ASNs":"AS197893","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"eltronik.net.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS43420","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"embnex.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS401661","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"emeraldonion.org","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS396507","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ensonnet.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS49840","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"erlion.tr","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS199099","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"esnet.kz","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"KZ:1","Example ASNs":"AS57013","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"estacaonet.net.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS265464","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ethr.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS30490","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"evolunetcorp.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS53003","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ExpressHost Ltd","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS197574","Source IDs":"N01, N38","Recommended Handling":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior."},{"Provider Family":"exstranet.bg","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BG:1","Example ASNs":"AS205872","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ezbit.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS197620","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"f-net.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS35695","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"f3netze.de","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS205100","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"faisalnetwork.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS149653","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"falaknet.online","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"SY:1","Example ASNs":"AS210557","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"fast-fiber.com.ph","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PH:1","Example ASNs":"AS213884","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"fasthost.ltd","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BG:1","Example ASNs":"AS200391","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"fastlines.it","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IT:1","Example ASNs":"AS60017","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"Fastly","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS54113","Source IDs":"N01","Recommended Handling":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review."},{"Provider Family":"fastweb.it","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IT:1","Example ASNs":"AS209353","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"fatimavideo.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS52688","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"fhpfibra.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS52937","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"fibernettv.com.co","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CO:1","Example ASNs":"AS270062","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"fiberpon.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"EC:1","Example ASNs":"AS273142","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"fixnet.com.tr","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS47288","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"flash-telecom.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS48120","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"flycom.net.ua","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS56400","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"flylifecuador.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"EC:1","Example ASNs":"AS273123","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"fns-holdings.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CY:1","Example ASNs":"AS206092","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"fnxtelecom.net.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS270923","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"foxpro.com.bd","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS142015","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ftc.net.co","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CO:1","Example ASNs":"AS273187","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"futuranet.net.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS266631","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"g-service.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS33991","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"galaxy.net.pk","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PK:1","Example ASNs":"AS139879","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"garratelecom.net.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS61851","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"gbd.hu","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"HU:1","Example ASNs":"AS211212","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"gdnet.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS39577","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"gec.af","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AF:1","Example ASNs":"AS58427","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"geckonet.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS198401","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"geniosoluciones.pro","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DO:1","Example ASNs":"AS273909","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ggbt.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS197793","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"GHOSTnet","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS12586","Source IDs":"N01, N48","Recommended Handling":"Disabled by default. Alert on the exact IP or ASN only when correlated with device-code abuse, scripting user agents, token replay, or unexpected Intune/device enrollment."},{"Provider Family":"globalconecta.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS271380","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"globallinkbd.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS140923","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"Google","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS15169","Source IDs":"N01","Recommended Handling":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review."},{"Provider Family":"Google Cloud","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS396982","Source IDs":"N01","Recommended Handling":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review."},{"Provider Family":"gss.biz.id","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ID:1","Example ASNs":"AS150493","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"gtncpl.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS135818","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"gwave.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS58347","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"hazi.ro","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RO:1","Example ASNs":"AS57403","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"highspeed-sy.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"SY:1","Example ASNs":"AS216472","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"hiperonline.com.tr","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS216192","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"hiraelectronicsandnetworking.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS150747","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"holainternet.com.co","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CO:1","Example ASNs":"AS273134","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"home-net.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS57789","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"homeoptic.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS43822","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"HOSTING INDUSTRY LIMITED","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS207461","Source IDs":"N01, N41","Recommended Handling":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior."},{"Provider Family":"hostingturkiye.com.tr","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS215761","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"hypecreation.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS13332","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"hypefox.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"SE:1","Example ASNs":"AS214365","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"idodns.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS42192","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"ind.in","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS153236","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"inetia.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS49785","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"inetrenzo.com.ar","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AR:1","Example ASNs":"AS274921","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"inetvip.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS53072","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"infomain.com.ar","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AR:1","Example ASNs":"AS272042","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"infronet.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS213498","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"Inios Oy","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"FI:1","Example ASNs":"AS209378","Source IDs":"N01, N38","Recommended Handling":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior."},{"Provider Family":"inmart.net.ua","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS196767","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"inovartelecomse.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS273433","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"intercable.cl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CL:1","Example ASNs":"AS266852","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"intercomhn.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"HN:1","Example ASNs":"AS273916","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"interlan.cl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CL:1","Example ASNs":"AS271843","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"intermax.net.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS201151","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"internetsahibi.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS42216","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling."},{"Provider Family":"interplus.net.ec","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"EC:1","Example ASNs":"AS273195","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"interzonafsa.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AR:1","Example ASNs":"AS274227","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"intexcom.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS50174","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ipxo.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"2","US ASN Count":"1","Foreign ASN Count":"1","Country Mix":"GB:1, US:1","Example ASNs":"AS201667, AS206069","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling."},{"Provider Family":"irtelcom.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS43530","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ispsupport.am","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AM:1","Example ASNs":"AS201884","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"IT7 Networks Inc","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CA:1","Example ASNs":"AS25820","Source IDs":"N01, N39","Recommended Handling":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior."},{"Provider Family":"jahwifi.mx","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"MX:1","Example ASNs":"AS273250","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"jarindo.id","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ID:1","Example ASNs":"AS136879","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"jetnetinternet.com.tr","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS200404","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"jetnetwork.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS270581","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"jknet.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS262909","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"joinnet.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS215851","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"joydebpurnetwork.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS139678","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"jumpnetcorp.com.ar","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AR:1","Example ASNs":"AS266705","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"kingwifiknetwork.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DO:1","Example ASNs":"AS274104","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"klikom.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS200750","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"komfort21vek.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS204144","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"komsomolske.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS56812","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"KorGrid","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS394711","Source IDs":"N01, N19, N35, N37","Recommended Handling":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review."},{"Provider Family":"ku.ac.ae","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AE:1","Example ASNs":"AS33847","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ledinternet.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS264014","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"leveltele.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS214268","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"levokumka.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS49854","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"lewtel.com.ar","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AR:1","Example ASNs":"AS264697","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"limnet.com.ua","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"2","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"UA:2","Example ASNs":"AS200814, AS207830","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"linkotek.in","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS141787","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"linyitnet.com.tr","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS212285","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"lts.org.ua","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS212695","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"luckyisp.in","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS149270","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"MAGIT'ST SRL","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RO:1","Example ASNs":"AS49468","Source IDs":"N01, N38","Recommended Handling":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior."},{"Provider Family":"magnacapax.fi","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"FI:1","Example ASNs":"AS203003","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling."},{"Provider Family":"magnates.co.za","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ZA:1","Example ASNs":"AS214209","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"management-alliance-group","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS6060","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"mapit.gov.in","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS141295","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"mapminas.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS52780","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"maraveca.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"VE:1","Example ASNs":"AS269901","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"mart.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS41302","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"mayaknet.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS47551","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"mayasoftbd.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS140906","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"mclaut.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS25133","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"mcs.ooo","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS47204","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"mega.net.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS197960","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"meganet.com.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS198158","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"meganet.net.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS263284","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"merdekanet.co.id","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ID:1","Example ASNs":"AS151595","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"metissrl.it","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IT:1","Example ASNs":"AS57558","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"micron.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS263351","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"microsattelecom.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS52543","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"microset.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS263536","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"Microsoft","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS8075","Source IDs":"N01, S05, X065, X066","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"midiatelecom.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS270433","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"mitel-inter.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS196786","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"mknet.biz","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS48494","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"modat.io","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"NL:1","Example ASNs":"AS209334","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"mojemedia.net.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS215253","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"morsejp.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"JP:1","Example ASNs":"AS55748","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"mottanet.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS52630","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"mozmail.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS25099","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"mpaps.co.ke","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"KE:1","Example ASNs":"AS329618","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"mscode.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS201132","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"multicarrier.com.mx","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"MX:1","Example ASNs":"AS270207","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"multilinkisp.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS142627","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"multimedialinktech.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ID:1","Example ASNs":"AS141098","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"multisystem.net.ua","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS43049","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"multitel-nortevision.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"VE:1","Example ASNs":"AS274206","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"multpontos.net.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS52904","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"multpontosfranca.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS271412","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"myce.net.cn","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CN:1","Example ASNs":"AS24426","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"nasstecairnet.net.pk","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PK:1","Example ASNs":"AS142647","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"naxosfibra.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS268983","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"nedataa.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS56268","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"neracom.bg","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BG:1","Example ASNs":"AS56606","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"nester.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS52008","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"net4india.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS17447","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"netagro.net.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS274714","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"netathomebd.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS139779","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"netexpress.info","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS149179","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"netgroup.ua","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS212463","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"netmax.com.tr","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS209275","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"netncr.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS135683","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"netpak.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS198910","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"netplay.com.ar","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AR:1","Example ASNs":"AS272090","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"netpontal.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS61756","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"netrelationbd.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS153337","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"netrexo.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS135815","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"netturbo.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS53158","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"netusinternet.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS203140","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"netvia.com.tr","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS207483","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"networldtron.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS7907","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"nextnet.co","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IQ:1","Example ASNs":"AS34515","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"nextstageinnovations.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS15012","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"nim-net.com.ua","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS212825","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ninux.org","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IT:1","Example ASNs":"AS197835","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"niutelecom.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CN:1","Example ASNs":"AS38337","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"nl-net.de","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS218831","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"NODE HOST LIMITED","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS198550","Source IDs":"N01, N38","Recommended Handling":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior."},{"Provider Family":"ntx55.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS57411","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"nurullah.tr","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS201030","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"nysanet.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS212623","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"o-net.com.ua","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS200582","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"octoheberg.fr","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"FR:1","Example ASNs":"AS216020","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"omicron.online","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS210135","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"omiplat.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS48433","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"onecablenetwork.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS401560","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"onstark.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS269427","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"onyphe.io","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"FR:1","Example ASNs":"AS213412","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"optikline.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS43273","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"optiknet.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS64429","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"Oracle Cloud","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS31898","Source IDs":"N01","Recommended Handling":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review."},{"Provider Family":"oriontelekom.rs","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RS:1","Example ASNs":"AS196886","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"othmarnetwork.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ID:1","Example ASNs":"AS135488","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"OVHcloud","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"FR:1","Example ASNs":"AS16276","Source IDs":"N01, S04, S06","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"Panq","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"NL:1","Example ASNs":"AS60262","Source IDs":"N01, N29, N30, N31","Recommended Handling":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review."},{"Provider Family":"pantanaltelecom.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS268757","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"pautina-net.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS197578","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"peravix.co.uk","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS204208","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling."},{"Provider Family":"pg19.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"2","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"RU:2","Example ASNs":"AS60246, AS206680","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"pinspb.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS56541","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"planet3communication.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS139728","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"PLAY2GO INTERNATIONAL LIMITED","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS215439","Source IDs":"N01, N38","Recommended Handling":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior."},{"Provider Family":"playmaisfibra.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS264051","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"plugartelecom.net.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS269182","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"pns.com.ve","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"VE:1","Example ASNs":"AS269771","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"pombonet.net.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS262988","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"powermediabd.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS139202","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"pozitivtelecom.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS44834","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"preciousnetcom.in","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS134299","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"prelution.nl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"NL:1","Example ASNs":"AS44541","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"prestomwill.cl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CL:1","Example ASNs":"AS267677","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"provedorsmartsp.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS271410","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"provinsat.com.ar","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AR:1","Example ASNs":"AS267889","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"qtcloud.co.jp","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"JP:1","Example ASNs":"AS24567","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"radarinternet.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS262880","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"rapidnetworkbd.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS141737","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"renewablefreedom.org","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS60729","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"riderz.pk","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PK:1","Example ASNs":"AS153844","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ring.net.id","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ID:1","Example ASNs":"AS141642","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"rocketcom.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS208142","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"rvcyberworld.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS139347","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"sanalsantral.com.tr","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS210949","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"scity.pro","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"KZ:1","Example ASNs":"AS208356","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"semfone.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS264217","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"serververs.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS218984","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"service-net.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS197868","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"setura.tr","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS218850","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"sevlush.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS43764","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"silkglobal.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DO:1","Example ASNs":"AS272073","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"sinaldoceu.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS268502","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"sircrosar.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"0","Country Mix":"ZZ:1","Example ASNs":"AS215462","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Disabled by default. Retain history and review current assignment, origin, and exact indicators before any enforcement."},{"Provider Family":"slv.net.ua","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS49588","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"solunet.com.ar","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AR:1","Example ASNs":"AS28111","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"soyuznet.com.ua","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS212432","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"spectrenetworks.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS40665","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"speedconnectfibra.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS52635","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"staritisp.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS147006","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"stepnet.kz","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"KZ:1","Example ASNs":"AS60286","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"stl-u.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS207423","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"stormnetwork.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IQ:1","Example ASNs":"AS212280","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"stupino.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS59574","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"suareznetwork.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DO:1","Example ASNs":"AS274326","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"sulharai.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS7411","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"superoptic.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AZ:1","Example ASNs":"AS200192","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"superredes.co","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CO:1","Example ASNs":"AS270075","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"surnet.com.tr","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS211496","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"synapse.net.ua","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS21308","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"tahtasolusindo.id","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ID:1","Example ASNs":"AS142352","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"tavriatrans.com.ua","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS42419","Source IDs":"N01, S01, S02, S03, S05","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"tbonet.net.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS264009","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"tcftelecom.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS263641","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"telecab.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS265201","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"telecable.cl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CL:1","Example ASNs":"AS274212","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"telsto.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS56985","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"telxe.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS266583","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ten.pe","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PE:1","Example ASNs":"AS274178","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"terabitvu.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS206803","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"tes.com.pk","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PK:1","Example ASNs":"AS138655","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"THE.Hosting clients","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"NL:1","Example ASNs":"AS213999","Source IDs":"N01, S01, S02, S03","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"timornet.id","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ID:1","Example ASNs":"AS140026","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"tlsoft.vn","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"VN:1","Example ASNs":"AS135915","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"tnd.vn","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"VN:1","Example ASNs":"AS140807","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"topnetbd.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS138953","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"topserver.vn","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"VN:1","Example ASNs":"AS154247","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"tornado.com.pk","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PK:1","Example ASNs":"AS139718","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"transunion.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CA:1","Example ASNs":"AS396126","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"triunfointernet.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS265914","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"turien.nl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"NL:1","Example ASNs":"AS203320","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"tutamail.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"FR:1","Example ASNs":"AS211590","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"tvtk.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS44678","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ugi.mx","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"MX:1","Example ASNs":"AS270226","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"umos.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS29233","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"unicomnet.co","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CO:1","Example ASNs":"AS274894","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"universofiber.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS266498","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"unredacted.org","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS401401","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"usbinternet.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS267325","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"uzumbank.uz","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UZ:1","Example ASNs":"AS48525","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"valornode.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS402170","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling."},{"Provider Family":"vcd.am","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"AM:1","Example ASNs":"AS201219","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"vdsmerkezi.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS205463","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"veenet.africa","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"KE:1","Example ASNs":"AS329437","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"virtualspaceprovedor.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS263947","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"vivanet.com.tr","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS212193","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"vizit-net.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS211947","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"vortexnetworks.in","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS151741","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"vozytelevision.org","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PE:1","Example ASNs":"AS273061","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"vrlan.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS203565","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"vsignal.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS34582","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"VSVK","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"NL:1","Example ASNs":"AS213511","Source IDs":"N01, S01, S02, S03, X031","Recommended Handling":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation."},{"Provider Family":"w9.com.tr","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"TR:1","Example ASNs":"AS211851","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"wave-net.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS132073","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"wdm.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS47329","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"weave.co.id","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"ID:1","Example ASNs":"AS149877","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"web-eleven.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS150170","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"webmaxnet.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IN:1","Example ASNs":"AS135765","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"westcall.spb.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS197052","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"westele.com.ua","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"UA:1","Example ASNs":"AS211250","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"winetfsa.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS271562","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"wirac.ba","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BA:1","Example ASNs":"AS59847","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"wnnet.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS61782","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"workcom.ec","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"EC:1","Example ASNs":"AS273034","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"worktelecombj.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS273470","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"x.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS63179","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"xnetfibra.com.br","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BR:1","Example ASNs":"AS270320","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"yapk-service.ru","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS216185","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"yesongit.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"2","US ASN Count":"0","Foreign ASN Count":"2","Country Mix":"CN:2","Example ASNs":"AS210634, AS213404","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"ynspartners.com","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DO:1","Example ASNs":"AS274095","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"zeronetbd.net","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BD:1","Example ASNs":"AS139839","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"zipnet.pl","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"PL:1","Example ASNs":"AS203667","Source IDs":"N01, S03","Recommended Handling":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling."},{"Provider Family":"sinoworldwidetrading.com","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"HK:1","Example ASNs":"AS211443","Source IDs":"S01, S02, N01, N62","Recommended Handling":"Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review."},{"Provider Family":"LSHIY LLC","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS32167","Source IDs":"X008, N01","Recommended Handling":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone."},{"Provider Family":"ITP-Solutions","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"DE:1","Example ASNs":"AS213250","Source IDs":"N52, N01","Recommended Handling":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone."},{"Provider Family":"Interserver","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS19318","Source IDs":"N52, N01","Recommended Handling":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone."},{"Provider Family":"Local NCC","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS212171","Source IDs":"N62, N01","Recommended Handling":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone."},{"Provider Family":"UP-NETWORK","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"CH:1","Example ASNs":"AS213929","Source IDs":"N62, N01","Recommended Handling":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone."},{"Provider Family":"AO ALMAZ","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"RU:1","Example ASNs":"AS210328","Source IDs":"N62, N01","Recommended Handling":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone."},{"Provider Family":"PebbleHost","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS201002","Source IDs":"N62, N01","Recommended Handling":"Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone."},{"Provider Family":"Railway","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS400940","Source IDs":"N58, N59, N01","Recommended Handling":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting."},{"Provider Family":"HZ-UK-AS HZ Hosting Ltd","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"BG:1","Example ASNs":"AS61046","Source IDs":"N59, N01","Recommended Handling":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting."},{"Provider Family":"NForce","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"NL:1","Example ASNs":"AS43350","Source IDs":"N60, N01","Recommended Handling":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting."},{"Provider Family":"Data Campus","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"HK:1","Example ASNs":"AS215929","Source IDs":"N60, N01","Recommended Handling":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting."},{"Provider Family":"Internet Solutions & Innovations","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"SC:1","Example ASNs":"AS211632","Source IDs":"N60, N01","Recommended Handling":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting."},{"Provider Family":"HOST TELECOM","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS214238","Source IDs":"N10, N01","Recommended Handling":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting."},{"Provider Family":"GREEN FLOID","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"1","Foreign ASN Count":"0","Country Mix":"US:1","Example ASNs":"AS204957","Source IDs":"N10, N01","Recommended Handling":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting."},{"Provider Family":"Global Connectivity Solutions","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"GB:1","Example ASNs":"AS215540","Source IDs":"N10, N06, N01","Recommended Handling":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting."},{"Provider Family":"HQSERV","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","US ASN Count":"0","Foreign ASN Count":"1","Country Mix":"IL:1","Example ASNs":"AS35758","Source IDs":"N61, N01","Recommended Handling":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting."}],"country_summary":[{"Country Code":"US","Country Name":"United States","Geography Scope":"US","Catalog ASN Count":"146","Enabled ASN Count":"94","T1 Count":"61","T2 Count":"10","T3 Count":"23","T4 Count":"52","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"BR","Country Name":"Brazil","Geography Scope":"Foreign","Catalog ASN Count":"97","Enabled ASN Count":"9","T1 Count":"2","T2 Count":"3","T3 Count":"4","T4 Count":"88","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"RU","Country Name":"Russia","Geography Scope":"Foreign","Catalog ASN Count":"96","Enabled ASN Count":"27","T1 Count":"20","T2 Count":"1","T3 Count":"7","T4 Count":"68","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"UA","Country Name":"Ukraine","Geography Scope":"Foreign","Catalog ASN Count":"82","Enabled ASN Count":"47","T1 Count":"43","T2 Count":"0","T3 Count":"4","T4 Count":"35","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"GB","Country Name":"United Kingdom","Geography Scope":"Foreign","Catalog ASN Count":"80","Enabled ASN Count":"55","T1 Count":"39","T2 Count":"6","T3 Count":"19","T4 Count":"16","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"IN","Country Name":"India","Geography Scope":"Foreign","Catalog ASN Count":"73","Enabled ASN Count":"47","T1 Count":"44","T2 Count":"1","T3 Count":"2","T4 Count":"26","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"MD","Country Name":"Moldova","Geography Scope":"Foreign","Catalog ASN Count":"51","Enabled ASN Count":"36","T1 Count":"35","T2 Count":"0","T3 Count":"1","T4 Count":"15","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"TR","Country Name":"Türkiye","Geography Scope":"Foreign","Catalog ASN Count":"47","Enabled ASN Count":"25","T1 Count":"9","T2 Count":"13","T3 Count":"3","T4 Count":"22","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"BD","Country Name":"Bangladesh","Geography Scope":"Foreign","Catalog ASN Count":"33","Enabled ASN Count":"7","T1 Count":"7","T2 Count":"0","T3 Count":"0","T4 Count":"26","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"DE","Country Name":"Germany","Geography Scope":"Foreign","Catalog ASN Count":"29","Enabled ASN Count":"19","T1 Count":"10","T2 Count":"2","T3 Count":"7","T4 Count":"10","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"PL","Country Name":"Poland","Geography Scope":"Foreign","Catalog ASN Count":"28","Enabled ASN Count":"4","T1 Count":"0","T2 Count":"3","T3 Count":"1","T4 Count":"24","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"HK","Country Name":"Hong Kong SAR China","Geography Scope":"Foreign","Catalog ASN Count":"27","Enabled ASN Count":"23","T1 Count":"18","T2 Count":"0","T3 Count":"5","T4 Count":"4","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"NL","Country Name":"Netherlands","Geography Scope":"Foreign","Catalog ASN Count":"24","Enabled ASN Count":"12","T1 Count":"10","T2 Count":"0","T3 Count":"3","T4 Count":"11","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"ID","Country Name":"Indonesia","Geography Scope":"Foreign","Catalog ASN Count":"20","Enabled ASN Count":"6","T1 Count":"6","T2 Count":"0","T3 Count":"0","T4 Count":"14","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"SC","Country Name":"Seychelles","Geography Scope":"Foreign","Catalog ASN Count":"20","Enabled ASN Count":"17","T1 Count":"16","T2 Count":"0","T3 Count":"1","T4 Count":"3","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"AR","Country Name":"Argentina","Geography Scope":"Foreign","Catalog ASN Count":"18","Enabled ASN Count":"2","T1 Count":"1","T2 Count":"0","T3 Count":"1","T4 Count":"16","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"VN","Country Name":"Vietnam","Geography Scope":"Foreign","Catalog ASN Count":"16","Enabled ASN Count":"9","T1 Count":"4","T2 Count":"3","T3 Count":"2","T4 Count":"7","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"IR","Country Name":"Iran","Geography Scope":"Foreign","Catalog ASN Count":"12","Enabled ASN Count":"11","T1 Count":"10","T2 Count":"0","T3 Count":"1","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"RO","Country Name":"Romania","Geography Scope":"Foreign","Catalog ASN Count":"12","Enabled ASN Count":"9","T1 Count":"7","T2 Count":"1","T3 Count":"1","T4 Count":"3","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"FR","Country Name":"France","Geography Scope":"Foreign","Catalog ASN Count":"11","Enabled ASN Count":"4","T1 Count":"1","T2 Count":"2","T3 Count":"1","T4 Count":"7","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"PK","Country Name":"Pakistan","Geography Scope":"Foreign","Catalog ASN Count":"11","Enabled ASN Count":"4","T1 Count":"4","T2 Count":"0","T3 Count":"0","T4 Count":"7","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"BG","Country Name":"Bulgaria","Geography Scope":"Foreign","Catalog ASN Count":"11","Enabled ASN Count":"7","T1 Count":"4","T2 Count":"0","T3 Count":"3","T4 Count":"4","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"MX","Country Name":"Mexico","Geography Scope":"Foreign","Catalog ASN Count":"10","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"10","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"CA","Country Name":"Canada","Geography Scope":"Foreign","Catalog ASN Count":"9","Enabled ASN Count":"4","T1 Count":"0","T2 Count":"1","T3 Count":"3","T4 Count":"5","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"KZ","Country Name":"Kazakhstan","Geography Scope":"Foreign","Catalog ASN Count":"9","Enabled ASN Count":"5","T1 Count":"3","T2 Count":"2","T3 Count":"0","T4 Count":"4","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"CN","Country Name":"China","Geography Scope":"Foreign","Catalog ASN Count":"8","Enabled ASN Count":"3","T1 Count":"3","T2 Count":"0","T3 Count":"0","T4 Count":"5","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"CO","Country Name":"Colombia","Geography Scope":"Foreign","Catalog ASN Count":"8","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"8","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"DO","Country Name":"Dominican Republic","Geography Scope":"Foreign","Catalog ASN Count":"8","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"8","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"IT","Country Name":"Italy","Geography Scope":"Foreign","Catalog ASN Count":"8","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"7","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"JP","Country Name":"Japan","Geography Scope":"Foreign","Catalog ASN Count":"8","Enabled ASN Count":"5","T1 Count":"5","T2 Count":"0","T3 Count":"0","T4 Count":"3","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"PA","Country Name":"Panama","Geography Scope":"Foreign","Catalog ASN Count":"9","Enabled ASN Count":"9","T1 Count":"0","T2 Count":"7","T3 Count":"2","T4 Count":"0","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"ZA","Country Name":"South Africa","Geography Scope":"Foreign","Catalog ASN Count":"8","Enabled ASN Count":"6","T1 Count":"6","T2 Count":"0","T3 Count":"0","T4 Count":"2","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"VE","Country Name":"Venezuela","Geography Scope":"Foreign","Catalog ASN Count":"7","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"7","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"EC","Country Name":"Ecuador","Geography Scope":"Foreign","Catalog ASN Count":"6","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"6","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"AT","Country Name":"Austria","Geography Scope":"Foreign","Catalog ASN Count":"5","Enabled ASN Count":"3","T1 Count":"3","T2 Count":"0","T3 Count":"0","T4 Count":"2","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"CL","Country Name":"Chile","Geography Scope":"Foreign","Catalog ASN Count":"5","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"4","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"IQ","Country Name":"Iraq","Geography Scope":"Foreign","Catalog ASN Count":"5","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"4","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"LT","Country Name":"Lithuania","Geography Scope":"Foreign","Catalog ASN Count":"5","Enabled ASN Count":"5","T1 Count":"1","T2 Count":"0","T3 Count":"4","T4 Count":"0","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"AE","Country Name":"United Arab Emirates","Geography Scope":"Foreign","Catalog ASN Count":"4","Enabled ASN Count":"2","T1 Count":"1","T2 Count":"1","T3 Count":"0","T4 Count":"2","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"AM","Country Name":"Armenia","Geography Scope":"Foreign","Catalog ASN Count":"4","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"4","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"EE","Country Name":"Estonia","Geography Scope":"Foreign","Catalog ASN Count":"4","Enabled ASN Count":"2","T1 Count":"1","T2 Count":"0","T3 Count":"1","T4 Count":"2","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"ES","Country Name":"Spain","Geography Scope":"Foreign","Catalog ASN Count":"4","Enabled ASN Count":"3","T1 Count":"1","T2 Count":"0","T3 Count":"2","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"IL","Country Name":"Israel","Geography Scope":"Foreign","Catalog ASN Count":"5","Enabled ASN Count":"4","T1 Count":"4","T2 Count":"0","T3 Count":"0","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"AL","Country Name":"Albania","Geography Scope":"Foreign","Catalog ASN Count":"3","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"2","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"CY","Country Name":"Cyprus","Geography Scope":"Foreign","Catalog ASN Count":"3","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"KE","Country Name":"Kenya","Geography Scope":"Foreign","Catalog ASN Count":"3","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"3","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"SG","Country Name":"Singapore","Geography Scope":"Foreign","Catalog ASN Count":"3","Enabled ASN Count":"3","T1 Count":"1","T2 Count":"1","T3 Count":"1","T4 Count":"0","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"ZZ","Country Name":"Unknown","Geography Scope":"Unknown","Catalog ASN Count":"3","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"3","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"AU","Country Name":"Australia","Geography Scope":"Foreign","Catalog ASN Count":"2","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"AZ","Country Name":"Azerbaijan","Geography Scope":"Foreign","Catalog ASN Count":"2","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"2","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"CH","Country Name":"Switzerland","Geography Scope":"Foreign","Catalog ASN Count":"3","Enabled ASN Count":"3","T1 Count":"1","T2 Count":"0","T3 Count":"2","T4 Count":"0","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"FI","Country Name":"Finland","Geography Scope":"Foreign","Catalog ASN Count":"2","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"2","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, session, and user baseline."},{"Country Code":"HN","Country Name":"Honduras","Geography Scope":"Foreign","Catalog ASN Count":"2","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"KR","Country Name":"South Korea","Geography Scope":"Foreign","Catalog ASN Count":"2","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"LB","Country Name":"Lebanon","Geography Scope":"Foreign","Catalog ASN Count":"2","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"LV","Country Name":"Latvia","Geography Scope":"Foreign","Catalog ASN Count":"2","Enabled ASN Count":"2","T1 Count":"1","T2 Count":"1","T3 Count":"0","T4 Count":"0","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"NG","Country Name":"Nigeria","Geography Scope":"Foreign","Catalog ASN Count":"2","Enabled ASN Count":"2","T1 Count":"2","T2 Count":"0","T3 Count":"0","T4 Count":"0","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"NZ","Country Name":"New Zealand","Geography Scope":"Foreign","Catalog ASN Count":"2","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"PE","Country Name":"Peru","Geography Scope":"Foreign","Catalog ASN Count":"2","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"2","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"RS","Country Name":"Serbia","Geography Scope":"Foreign","Catalog ASN Count":"2","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"SE","Country Name":"Sweden","Geography Scope":"Foreign","Catalog ASN Count":"2","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"2","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"SY","Country Name":"Syria","Geography Scope":"Foreign","Catalog ASN Count":"2","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"2","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"UZ","Country Name":"Uzbekistan","Geography Scope":"Foreign","Catalog ASN Count":"2","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"2","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"AF","Country Name":"Afghanistan","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"AO","Country Name":"Angola","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"BA","Country Name":"Bosnia & Herzegovina","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"BY","Country Name":"Belarus","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"CW","Country Name":"Curaçao","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"CZ","Country Name":"Czechia","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"GT","Country Name":"Guatemala","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"HU","Country Name":"Hungary","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"IE","Country Name":"Ireland","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"0","T3 Count":"1","T4 Count":"0","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"IS","Country Name":"Iceland","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"1","T1 Count":"0","T2 Count":"1","T3 Count":"0","T4 Count":"0","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"KG","Country Name":"Kyrgyzstan","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"KN","Country Name":"St. Kitts & Nevis","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"LY","Country Name":"Libya","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"MY","Country Name":"Malaysia","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"PH","Country Name":"Philippines","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"PS","Country Name":"Palestinian Territories","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"PT","Country Name":"Portugal","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"PY","Country Name":"Paraguay","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"0","T1 Count":"0","T2 Count":"0","T3 Count":"0","T4 Count":"1","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."},{"Country Code":"TW","Country Name":"Taiwan","Geography Scope":"Foreign","Catalog ASN Count":"1","Enabled ASN Count":"1","T1 Count":"1","T2 Count":"0","T3 Count":"0","T4 Count":"0","Event-Country Policy":"Unspecified","Operational Notes":"This is the ASN holder registration country. Apply employee-location policy to event-time IP geolocation, then correlate ASN, VPN/proxy, device, and user baseline."}],"detection_patterns":[{"Detection":"Successful interactive sign-in from T1/T2 network","Priority":"High","Event Sources":"Entra/Google sign-in, ASN, IP, auth type, device, user agent","Logic":"Successful employee interactive login where ASN tier is T1 or T2 and the ASN is enabled.","Corroboration":"ASN match is high-priority context, not automatic proof.","ASN / Country Role":"ASN tier is infrastructure context. Event-time IP country, not ASN registration country, drives country policy.","Response":"Triage immediately; verify user intent, device, MFA, session, and post-authentication behavior.","ATT&CK / TTP":"T1078.004","Source IDs":"S02, N17, N34","Notes":"ASN match is high-priority context, not automatic proof."},{"Detection":"Hosting or VPN sign-in plus novelty","Priority":"High","Event Sources":"Sign-in, device compliance, user baseline, event-time geolocation","Logic":"Hosting/VPN/proxy ASN plus new ASN for user, new device, unmanaged device, or unusual event country.","Corroboration":"Travel and approved VPN use can explain novelty.","ASN / Country Role":"ASN tier is infrastructure context. Event-time IP country, not ASN registration country, drives country policy.","Response":"Step up authentication or investigate; contain only with corroboration.","ATT&CK / TTP":"T1078.004; T1090","Source IDs":"N17, N34","Notes":"Travel and approved VPN use can explain novelty."},{"Detection":"No-employee or prohibited event country","Priority":"High","Event Sources":"Event IP geolocation, user HR/location policy, ASN and anonymizer flags","Logic":"Successful employee sign-in where event-time IP country is marked No Employees or Prohibited.","Corroboration":"Use event IP country, not ASN registration country. VPN exits can mask actor location.","ASN / Country Role":"ASN tier is infrastructure context. Event-time IP country, not ASN registration country, drives country policy.","Response":"Block or step up according to policy; investigate exceptions.","ATT&CK / TTP":"T1078.004","Source IDs":"N01, N24, N25","Notes":"Use event IP country, not ASN registration country. VPN exits can mask actor location."},{"Detection":"Impossible travel with infrastructure change","Priority":"High","Event Sources":"Sign-in times, event IP countries, ASN, device/session ID","Logic":"Same identity succeeds from distant geographies or incompatible ASNs within an infeasible interval.","Corroboration":"Cloud and VPN geolocation can be noisy; weigh device and session continuity.","ASN / Country Role":"ASN tier is infrastructure context. Event-time IP country, not ASN registration country, drives country policy.","Response":"Revoke suspicious sessions and validate both events.","ATT&CK / TTP":"T1078.004","Source IDs":"N17, N34","Notes":"Cloud and VPN geolocation can be noisy; weigh device and session continuity."},{"Detection":"Password spray then success","Priority":"High","Event Sources":"Failure and success logs, source ASN/family, targeted accounts","Logic":"Multiple failures across accounts followed by success from related proxy, VPN, or hosting infrastructure.","Corroboration":"Aggregate across rotating IPs and provider families.","ASN / Country Role":"ASN tier is infrastructure context. Event-time IP country, not ASN registration country, drives country policy.","Response":"Reset or protect affected account; inspect source cluster and subsequent access.","ATT&CK / TTP":"T1110.003; T1078","Source IDs":"N06, N07, N35","Notes":"Aggregate across rotating IPs and provider families."},{"Detection":"Distributed password spray","Priority":"High","Event Sources":"Authentication failures, account set, timestamps, source ASN/family","Logic":"Aggregate failures by tenant/account set/password pattern/time window rather than per source IP.","Corroboration":"Residential and commercial proxy rotation defeats per-IP thresholds.","ASN / Country Role":"ASN tier is infrastructure context. Event-time IP country, not ASN registration country, drives country policy.","Response":"Rate-limit, block proven exact IPs, and investigate any success.","ATT&CK / TTP":"T1110.003","Source IDs":"N35","Notes":"Residential and commercial proxy rotation defeats per-IP thresholds."},{"Detection":"Cross-ASN same-user session sequence","Priority":"High","Event Sources":"Sign-in, token/session ID, ASN, IP, user agent","Logic":"Same user or token appears from different ASNs within minutes, especially cloud VPS followed by residential or commercial VPN.","Corroboration":"Legitimate mobile/VPN changes can occur; session continuity raises confidence.","ASN / Country Role":"ASN tier is infrastructure context. Event-time IP country, not ASN registration country, drives country policy.","Response":"Inspect token/session IDs, revoke confirmed replay, and hunt related activity.","ATT&CK / TTP":"T1550.001; T1090","Source IDs":"N17, N34","Notes":"Legitimate mobile/VPN changes can occur; session continuity raises confidence."},{"Detection":"Suspicious login followed by authenticator enrollment","Priority":"Critical","Event Sources":"Sign-in, authentication-method change, device registration audit","Logic":"Unexpected device-code or token use followed within about 15 minutes by passkey, phone, software-token, Intune, Device Registration Service, PRT-capable, or burst multi-device enrollment, including non-interactive sign-ins.","Corroboration":"Approved onboarding should be allowlisted by workflow and device.","ASN / Country Role":"ASN tier is infrastructure context. Event-time IP country, not ASN registration country, drives country policy.","Response":"Remove rogue method/device, reset account, then revoke sessions.","ATT&CK / TTP":"T1098; T1556","Source IDs":"N23, N27, N34, N48, N50","Notes":"Approved onboarding should be allowlisted by workflow and device."},{"Detection":"PRT or rogue-device persistence","Priority":"Critical","Event Sources":"Device registration, PRT indicators, sign-in and audit logs","Logic":"New device registration or PRT-capable enrollment after suspected AiTM or token theft.","Corroboration":"Session revocation alone may not remove device-backed persistence.","ASN / Country Role":"ASN tier is infrastructure context. Event-time IP country, not ASN registration country, drives country policy.","Response":"For confirmed compromise, inspect and disable every rogue device, revoke tokens and sessions, reset credentials, remove inbox or consent persistence, and consider temporary account disablement.","ATT&CK / TTP":"T1098; T1550.001","Source IDs":"N20, N27, N34, N48, N50","Notes":"Session revocation alone may not remove device-backed persistence."},{"Detection":"Device-code phishing or token replay","Priority":"Critical","Event Sources":"OAuth/device-code events, token/session IDs, IP, UA, app ID","Logic":"Unexpected OAuth device-code flow, token replay, or the same identity/session across different IP, ASN, user-agent, and interactive/non-interactive token streams.","Corroboration":"Validate approved CLI and device-code workflows.","ASN / Country Role":"ASN tier is infrastructure context. Event-time IP country, not ASN registration country, drives country policy.","Response":"Revoke tokens, remove consent/persistence, reset account, and hunt post-authentication actions.","ATT&CK / TTP":"T1528; T1550.001; T1078.004","Source IDs":"N15, N20, N32, N48, N50","Notes":"Validate approved CLI and device-code workflows."},{"Detection":"Graph reconnaissance burst","Priority":"High","Event Sources":"Graph audit, application ID, user, paths, timestamps","Logic":"After unusual sign-in, at least 10 requests spanning 3 object categories or 6 Graph paths within 30 minutes.","Corroboration":"Tune for administrators and automation accounts.","ASN / Country Role":"ASN, anonymizer, and event-time country increase confidence; SaaS behavior is primary.","Response":"Investigate identity, app, and data access; revoke confirmed malicious sessions.","ATT&CK / TTP":"T1087; T1526","Source IDs":"N17, N23, N34, N48, N50","Notes":"Tune for administrators and automation accounts."},{"Detection":"Scripting user agent with broad file access","Priority":"High","Event Sources":"FileAccessed, user agent, app ID, file count, ASN","Logic":"python-requests/2.28.1 or 2.34.2, python-httpx, PowerShell, curl, or other rare scripting agents access at least 100 files in 2 hours or follow token/device enrollment.","Corroboration":"Known backup and migration tools require allowlists.","ASN / Country Role":"ASN, anonymizer, and event-time country increase confidence; SaaS behavior is primary.","Response":"Validate automation owner; investigate and contain unexplained access.","ATT&CK / TTP":"T1119; T1530","Source IDs":"N23, N34, N48, N50","Notes":"Known backup and migration tools require allowlists."},{"Detection":"Anonymizer plus high-volume exfiltration","Priority":"Critical","Event Sources":"File events, bytes, ASN/anonymizer class, user/session","Logic":"VPN/proxy/anonymizer source plus at least 5 GB or 1,000 file events in 2 hours.","Corroboration":"Use a slower companion rule to catch low-and-slow theft.","ASN / Country Role":"ASN, anonymizer, and event-time country increase confidence; SaaS behavior is primary.","Response":"Suspend session and investigate data scope.","ATT&CK / TTP":"T1530; T1567","Source IDs":"N23, N26","Notes":"Use a slower companion rule to catch low-and-slow theft."},{"Detection":"Low-and-slow SaaS exfiltration","Priority":"High","Event Sources":"FileAccessed, repository/category count, time series, ASN","Logic":"Unusual identity or anonymizer steadily accesses multiple sensitive repositories below burst thresholds.","Corroboration":"Tenant baselines and job role are essential.","ASN / Country Role":"ASN, anonymizer, and event-time country increase confidence; SaaS behavior is primary.","Response":"Compare with role baseline and investigate unexplained cross-repository access.","ATT&CK / TTP":"T1530; T1119","Source IDs":"N17, N23, N26","Notes":"Tenant baselines and job role are essential."},{"Detection":"Known malicious or anomalous application ID","Priority":"High","Event Sources":"Sign-in, service principal, consent, Graph audit","Logic":"Observed client/resource IDs 9199bf20-a13f-4107-85dc-02114787ef48, c999ed3e-27ae-4cb3-b3a2-46b056af63d3, or campaign-linked application IDs.","Corroboration":"Application IDs can be reused in legitimate testing; validate tenant inventory.","ASN / Country Role":"ASN, anonymizer, and event-time country increase confidence; SaaS behavior is primary.","Response":"Validate consent and expected use; revoke and investigate if unauthorized.","ATT&CK / TTP":"T1528","Source IDs":"N23","Notes":"Application IDs can be reused in legitimate testing; validate tenant inventory."},{"Detection":"VPS-origin management HTTPS anomaly","Priority":"Critical","Event Sources":"Firewall flow, URL, bytes, duration, source ASN","Logic":"Management HTTPS from hosting/VPS source lasting over 100 seconds and transferring over 1 MB.","Corroboration":"Tune for approved administrators and scanners.","ASN / Country Role":"VPS or hosting source raises priority; management-plane behavior is primary.","Response":"Isolate management plane, collect configuration/audit logs, and hunt account/VPN changes.","ATT&CK / TTP":"T1190","Source IDs":"N09","Notes":"Tune for approved administrators and scanners."},{"Detection":"FortiGate Console Chaos chain","Priority":"Critical","Event Sources":"FortiGate config/admin logs, VPN changes, AD replication","Logic":"jsconsole or management access followed by account creation, VPN configuration change, or DCSync behavior.","Corroboration":"Sequence is higher confidence than any source ASN alone.","ASN / Country Role":"VPS or hosting source raises priority; management-plane behavior is primary.","Response":"Contain appliance and identity plane; rotate credentials and inspect domain compromise.","ATT&CK / TTP":"T1190; T1136; T1003.006","Source IDs":"N09, N54","Notes":"Sequence is higher confidence than any source ASN alone."},{"Detection":"SonicWall VPN rapid-impact chain","Priority":"Critical","Event Sources":"SonicWall auth, EDR, SMB/RDP, AnyDesk/FileZilla, file encryption","Logic":"Hosting/VPN-origin login followed within hours by lateral movement, credential access, remote tools, exfiltration, or encryption.","Corroboration":"Arctic Wolf observed rapid impact; exact timing varies by intrusion.","ASN / Country Role":"ASN tier is infrastructure context. Event-time IP country, not ASN registration country, drives country policy.","Response":"Contain VPN session and endpoints; inspect credential exposure and ransomware staging.","ATT&CK / TTP":"T1133; T1078; T1021; T1486","Source IDs":"N06, N07, N12, N54, N56, N47","Notes":"Arctic Wolf observed rapid impact; exact timing varies by intrusion."},{"Detection":"Separated auth, recon, and exfil sources","Priority":"Critical","Event Sources":"Identity/session IDs across sign-in, Graph, and file audit","Logic":"Correlate one identity across different source IPs/ASNs for authentication, Graph reconnaissance, and data exfiltration.","Corroboration":"Do not require one source IP across the attack chain.","ASN / Country Role":"ASN tier is infrastructure context. Event-time IP country, not ASN registration country, drives country policy.","Response":"Treat as coordinated session theft unless validated.","ATT&CK / TTP":"T1078; T1090; T1530","Source IDs":"N17, N23, N34, N48, N50","Notes":"Do not require one source IP across the attack chain."},{"Detection":"Exact IOC match with time scope","Priority":"High","Event Sources":"IOC type/value, source, observed dates, current mapping","Logic":"Exact IP, CIDR, domain, hash, or app ID matches a published indicator within its review TTL.","Corroboration":"Stale IP mappings and shared infrastructure are common.","ASN / Country Role":"Compare observation-time and current ASN/holder. Country is not attribution.","Response":"Validate current routing/ownership and campaign context before blocking or attribution.","ATT&CK / TTP":"Indicator lifecycle","Source IDs":"S02, N33, N39, N40, N41, N45, N48, N49, N52, N54, N55, N57","Notes":"Stale IP mappings and shared infrastructure are common."},{"Detection":"Broad cloud or CDN ASN-only match","Priority":"Informational","Event Sources":"ASN, exact IOC, device, user baseline, application","Logic":"Sign-in or traffic only matches a disabled broad cloud/CDN ASN without other anomalies.","Corroboration":"Prevents false positives from AWS, Google, Microsoft, Cloudflare, Akamai, and similar networks.","ASN / Country Role":"ASN tier is infrastructure context. Event-time IP country, not ASN registration country, drives country policy.","Response":"Record as context; do not alert or block without exact IOC or behavior.","ATT&CK / TTP":"Context-only control","Source IDs":"N17, N20, N34","Notes":"Prevents false positives from AWS, Google, Microsoft, Cloudflare, Akamai, and similar networks."},{"Detection":"Workload identity ARM credential and destruction sequence","Priority":"Critical","Event Sources":"Entra service-principal sign-ins; Azure Activity and ARM logs","Logic":"Novel service-principal source or enumeration burst followed by Storage ListKeys, resource deletion, or recovery/backup-lock deletion attempts.","Corroboration":"Require workload-identity novelty, privilege context, and destructive or credential-access operations; shared cloud sources and scripting agents are not sufficient alone.","ASN / Country Role":"ASN is supporting context for workload identities; behavior and credential lineage are primary.","Response":"Disable or rotate the service-principal credential, contain affected resources, restore protections, and scope accessed keys.","ATT&CK / TTP":"T1078.004; T1526; T1485","Source IDs":"N52","Notes":"Initial access may remain unknown; baseline legitimate automation and break-glass workflows."},{"Detection":"SSPR takeover to pipeline and Kubernetes credentials","Priority":"Critical","Event Sources":"Entra audit; Azure DevOps audit; repository and Kubernetes logs","Logic":"Unexpected self-service password reset or auth-method registration followed by Azure DevOps enumeration, pipeline or service-connection edits, kubeconfig collection, or tunnel/RMM deployment.","Corroboration":"Correlate recovery event, identity novelty, pipeline access, and credential retrieval. Legitimate recovery and engineering administration require allowlists.","ASN / Country Role":"Hosting or anonymizer context raises priority; the identity-to-pipeline sequence is primary.","Response":"Revoke identity, pipeline, cloud, and cluster credentials; remove persistence and inspect downstream deployments.","ATT&CK / TTP":"T1098; T1552; T1078","Source IDs":"N53","Notes":"Resetting the initial password alone does not remove harvested pipeline or cluster credentials."},{"Detection":"Valid VPN account to domain-root GPO impact","Priority":"Critical","Event Sources":"FortiGate VPN; Windows 5137/5136/4663/4657; Sysmon 11; SYSVOL integrity","Logic":"Novel or unexpected VPN valid-account access followed by domain-root GPO creation or gPLink changes, non-replication SYSVOL writes, and firewall or security-policy weakening.","Corroboration":"Do not require encryptor execution. Baseline approved GPO deployment, replication, and emergency administration.","ASN / Country Role":"Source ASN and event country are risk enrichments; valid-account VPN and domain-control changes are primary.","Response":"Contain the VPN session and account, disable malicious GPOs, restore SYSVOL and security policy, and scope extortion activity.","ATT&CK / TTP":"T1133; T1078; T1484.001; T1562.004","Source IDs":"N54","Notes":"The source report had logging gaps and did not prove Fortinet exploitation or individual IP roles."},{"Detection":"Conditional multi-ASN fast-flux phishing","Priority":"High","Event Sources":"Passive DNS; DNS logs; web telemetry; identity sign-ins","Logic":"Domain delegates through the reported DNS pattern and rotates across at least four ASNs and four IPs, with at least three ASNs from the source seed set, plus phishing or credential-capture evidence.","Corroboration":"Require the full diversity/delegation pattern or brand/identity behavior. DNSPod and every seed ASN are not malicious by themselves.","ASN / Country Role":"ASN diversity is a correlation feature, not a provider verdict.","Response":"Block the malicious domain and session, preserve DNS history, and pivot across the rotating infrastructure.","ATT&CK / TTP":"T1566; T1583.001; T1090","Source IDs":"N38","Notes":"Publication explicitly warns that ordinary hosting can appear in the rotation."},{"Detection":"Edge exploitation exact-IOC and artifact correlation","Priority":"Critical","Event Sources":"Citrix/FortiGate/web logs; EDR; DNS and network telemetry","Logic":"Exact Kapibala or Citrix source, C2, webshell path/hash, or wildcard domain appears with exploit requests, configuration change, process execution, or credential access.","Corroboration":"Exact IOC alone starts a retro-hunt; containment requires target-side evidence or a confirmed malicious session.","ASN / Country Role":"Current origin is recorded separately from campaign attribution and does not implicate the provider.","Response":"Isolate the appliance or host, preserve volatile evidence, rotate exposed credentials, and search for persistence.","ATT&CK / TTP":"T1190; T1505.003; T1059","Source IDs":"N39, N40","Notes":"One Citrix attempt failed against the vendor sensor; current ASN mapping may differ from stale search results."},{"Detection":"Unauthorized MeshAgent or tunnel plus ransomware behavior","Priority":"Critical","Event Sources":"EDR; network telemetry; RMM inventory; Windows event logs","Logic":"Unapproved MeshAgent, Atera, ngrok, Cloudflared, Chisel, or Ligolo activity correlated with exact C2, BYOVD, credential access, recovery inhibition, log deletion, or bulk exfiltration.","Corroboration":"Dual-use tools require inventory and behavioral corroboration.","ASN / Country Role":"Provider-wide blocking is not supported by one endpoint; exact C2 and behavior are primary.","Response":"Contain the endpoint and remote-management channel, rotate credentials, restore recovery controls, and scope exfiltration.","ATT&CK / TTP":"T1219; T1562.001; T1490; T1567","Source IDs":"N41, N47, N56","Notes":"Initial access can be unknown and tooling is legitimate in approved workflows."},{"Detection":"Dormant service-account spray and rapid source switch","Priority":"High","Event Sources":"Entra sign-ins; service-account inventory; user-agent and ASN history","Logic":"Stale TeamFiltration user agent or distributed failures against dormant service accounts followed by success and a rapid switch from AWS EC2 spray infrastructure to a different VPN/hosting ASN.","Corroboration":"Require account dormancy or unusual use, failed-to-success sequence, user-agent match, or post-access behavior. Do not alert on AWS ranges alone.","ASN / Country Role":"Rapid ASN change is more selective than provider membership; AWS and VPN hosting are shared.","Response":"Disable or rotate the forgotten credential, revoke sessions, review service dependencies, and hunt tenant-wide spray targets.","ATT&CK / TTP":"T1110.003; T1078; T1090","Source IDs":"N57","Notes":"Proofpoint observed more than 5,700 targeted accounts across 28 tenants and seven compromised service accounts."},{"Detection":"Historical First VPN Service activity","Priority":"High","Event Sources":"VPN, identity, edge, DNS, and proxy logs","Logic":"Historical match to FBI-listed 1VPNS IPs or domains during the relevant period, especially with failed-to-success access, unfamiliar device/MFA/session, scanning, malware deployment, or exfiltration.","Corroboration":"The May and older exit IPs may be reassigned. Require time alignment and current ownership/service validation for present-day action.","ASN / Country Role":"Do not transfer the sanctioned reseller label to unrelated underlying hosting ASNs.","Response":"Use for retro-hunting and incident scoping; block current infrastructure only after revalidation.","ATT&CK / TTP":"T1090; T1133; T1078; T1046; T1110","Source IDs":"N44, N45","Notes":"The service was disrupted and later sanctioned; exact IPs are retained as historical IOCs, not a current blocklist."}],"community_feeds":[{"Feed":"IPsum","Snapshot / Update":"2026-09-29","Unique Indicators":"121838","Coverage / Signal":"IPv4 with source-count score; score >=3: 17604; score >=5: 4242","Current State":"Tue, 29 Sep 2026 03:00:38 +0200","Recommended Use":"Exact-IP enrichment and short-TTL hunting; preserve score and snapshot date.","Limitations":"Inputs are not independent. 47,278 IPs overlap Data-Shield, including 14,466 IPsum score >=3 addresses.","Source IDs":"N02","URL":"https://github.com/stamparm/ipsum"},{"Feed":"mzyui HTTP proxy list","Snapshot / Update":"2026-08-29","Unique Indicators":"63797","Coverage / Signal":"IPv4:port endpoints; 53395 unique IPv4","Current State":"Rejected: stale and unvalidated","Recommended Use":"Discovery only; reject for enforcement until updater health and independent endpoint validation recover.","Limitations":"Byte-identical for 31.8 days with 143 consecutive updater failures.","Source IDs":"N03","URL":"https://github.com/mzyui/proxy-list"},{"Feed":"Data-Shield IPv4 Blocklist","Snapshot / Update":"2026-09-29","Unique Indicators":"92896","Coverage / Signal":"IPv4; overlap with IPsum: 47278","Current State":"2026-09-29 20:05:41","Recommended Use":"Exact-IP corroboration with source/date retention.","Limitations":"Large overlap with IPsum prevents treating cross-list presence as independent evidence.","Source IDs":"N04","URL":"https://github.com/duggytuxy/Data-Shield_IPv4_Blocklist"},{"Feed":"Cisco Talos April 2024 brute-force IOCs","Snapshot / Update":"2024-04-16","Unique Indicators":"3926","Coverage / Signal":"IPv4 plus credential observations","Current State":"Historical snapshot","Recommended Use":"Historical hunting and campaign-time ASN context for VPN, web-authentication, and SSH brute force.","Limitations":"Keep campaign-time attribution separate from current routing. Source IPs can be reassigned; no ASN-wide provider implication.","Source IDs":"N05, N35","URL":"https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/"},{"Feed":"Ransomware.live IoCs","Snapshot / Update":"2026-09-29","Unique Indicators":"2564","Coverage / Signal":"Heterogeneous group IOCs","Current State":"Dynamic page checked 2026-09-29","Recommended Use":"Discovery and corroboration; retain group, type, date, and original provenance where available.","Limitations":"Network rows mix bare IP, IP:port, and CIDR and lack reliable per-row observation dates/original references. Revalidate exact indicators; never promote an ASN from presence alone.","Source IDs":"N33","URL":"https://www.ransomware.live/ioc"},{"Feed":"Current community-feed union","Snapshot / Update":"2026-09-29","Unique Indicators":"218847","Coverage / Signal":"IPv4; all-three overlap: 60","Current State":"Mixed; see individual rows","Recommended Use":"Prioritize exact indicators aligned with fresh tenant telemetry and observed TTPs.","Limitations":"Cross-list overlap is not independent corroboration. Feed volume alone does not support ASN-level malicious attribution.","Source IDs":"N02, N03, N04","URL":"https://github.com/stamparm/ipsum"}],"review_only":[{"ASN":"AS34202","Network Name":"CLOUVIDER-THN2 Clouvider Limited","Provider Family":"Clouvider","Country":"GB","Route Status":"Announced","Tier":"T3 Context","Reason Disabled":"Related Clouvider hosting / transit network","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Active Clouvider-related ASN without direct reviewed identity-attack evidence at the ASN level. Kept disabled as provider-family context; do not infer malicious operation or provider complicity.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N10, N11, N12, N13, N14, N01"},{"ASN":"AS43878","Network Name":"EUROPE-CONNECTED Clouvider Limited","Provider Family":"Clouvider","Country":"GB","Route Status":"Announced","Tier":"T3 Context","Reason Disabled":"Related Clouvider hosting / transit network","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Active Clouvider-related ASN without direct reviewed identity-attack evidence at the ASN level. Kept disabled as provider-family context; do not infer malicious operation or provider complicity.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N10, N11, N12, N13, N14, N01"},{"ASN":"AS57724","Network Name":"DDOS-GUARD DDOS-GUARD LTD","Provider Family":"DDoS-Guard","Country":"RU","Route Status":"Announced","Tier":"T3 Context","Reason Disabled":"Published campaign infrastructure in shared hosting or VPN space","Abuse Band":"","Abuse %":"","FP Risk":"Medium","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS57724 across UNC6671 multi-brand vishing, AiTM, and SaaS extortion. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N17, N01"},{"ASN":"AS60262","Network Name":"PANQ Panq B.V.","Provider Family":"Panq","Country":"NL","Route Status":"Announced","Tier":"T3 Context","Reason Disabled":"Related provider or broad shared-service context","Abuse Band":"","Abuse %":"","FP Risk":"Medium","Evidence Summary":"Active related network for Panq. No direct provider-level malicious designation was established; retain as disabled family or shared-service context.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N29, N30, N31, N01"},{"ASN":"AS202791","Network Name":"CLOUDSRV-ANY Clouvider Limited","Provider Family":"Clouvider","Country":"GB","Route Status":"Announced","Tier":"T3 Context","Reason Disabled":"Related Clouvider hosting / transit network","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Active Clouvider-related ASN without direct reviewed identity-attack evidence at the ASN level. Kept disabled as provider-family context; do not infer malicious operation or provider complicity.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N10, N11, N12, N13, N14, N01"},{"ASN":"AS202792","Network Name":"CLOUD-TRANSIT Clouvider Limited","Provider Family":"Clouvider","Country":"GB","Route Status":"Announced","Tier":"T3 Context","Reason Disabled":"Related Clouvider hosting / transit network","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Active Clouvider-related ASN without direct reviewed identity-attack evidence at the ASN level. Kept disabled as provider-family context; do not infer malicious operation or provider complicity.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N10, N11, N12, N13, N14, N01"},{"ASN":"AS206136","Network Name":"CLOUDSRV-NORTH Clouvider Limited","Provider Family":"Clouvider","Country":"GB","Route Status":"Not currently originating","Tier":"T3 Context","Reason Disabled":"Related Clouvider hosting / transit network","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Active Clouvider-related ASN without direct reviewed identity-attack evidence at the ASN level. Kept disabled as provider-family context; do not infer malicious operation or provider complicity.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N10, N11, N12, N13, N14, N01"},{"ASN":"AS206822","Network Name":"CLOUDNET Clouvider Limited","Provider Family":"Clouvider","Country":"GB","Route Status":"Announced","Tier":"T3 Context","Reason Disabled":"Related Clouvider hosting / transit network","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Active Clouvider-related ASN without direct reviewed identity-attack evidence at the ASN level. Kept disabled as provider-family context; do not infer malicious operation or provider complicity.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N10, N11, N12, N13, N14, N01"},{"ASN":"AS206848","Network Name":"UKCDN Clouvider Limited","Provider Family":"Clouvider","Country":"GB","Route Status":"Announced","Tier":"T3 Context","Reason Disabled":"Related Clouvider hosting / transit network","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Active Clouvider-related ASN without direct reviewed identity-attack evidence at the ASN level. Kept disabled as provider-family context; do not infer malicious operation or provider complicity.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N10, N11, N12, N13, N14, N01"},{"ASN":"AS207019","Network Name":"TNCL Clouvider Limited","Provider Family":"Clouvider","Country":"GB","Route Status":"Announced","Tier":"T3 Context","Reason Disabled":"Related Clouvider hosting / transit network","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Active Clouvider-related ASN without direct reviewed identity-attack evidence at the ASN level. Kept disabled as provider-family context; do not infer malicious operation or provider complicity.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N10, N11, N12, N13, N14, N01"},{"ASN":"AS207158","Network Name":"WORLDCDN Clouvider Limited","Provider Family":"Clouvider","Country":"GB","Route Status":"Announced","Tier":"T3 Context","Reason Disabled":"Related Clouvider hosting / transit network","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Active Clouvider-related ASN without direct reviewed identity-attack evidence at the ASN level. Kept disabled as provider-family context; do not infer malicious operation or provider complicity.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N10, N11, N12, N13, N14, N01"},{"ASN":"AS6060","Network Name":"MAGI-NET-GW - Management Alliance Group Inc.","Provider Family":"management-alliance-group","Country":"US","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"AS6060 is currently unannounced but remains in the live Spamhaus ASN-DROP feed. Spamhaus specifically covers hijacked or revived dormant ASNs and re-evaluates listings daily. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as MAGI-NET-GW (management-alliance-group).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS7411","Network Name":"WINTERSTORM - StormNet Communications","Provider Family":"sulharai.com","Country":"US","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"AS7411 is unannounced in current routing data and is present in live Spamhaus ASN-DROP, consistent with DROP's coverage of hijacked/revived dormant resources. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as WINTERSTORM (sulharai.com).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS7907","Network Name":"NETWORD-CORP - Networldtron Corp","Provider Family":"networldtron.net","Country":"US","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"AS7907 is unannounced in current routing data and is present in live Spamhaus ASN-DROP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NETWORD-CORP (networldtron.net).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS8075","Network Name":"MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation","Provider Family":"Microsoft","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Broad Microsoft cloud / first-party false-positive risk","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Microsoft owns AS8075. Exclude it from ASN-only identity alerts because first-party services, integrations and Microsoft-hosted workloads can originate there. AS8075 is Microsoft's global network and carries Azure and Microsoft online services. It is not in current Spamhaus ASN-DROP. ASN-only matching would create severe false positives in a Microsoft 365 environment and can also match tenant-to-tenant or platform traffic.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S05, X065, X066, N01"},{"ASN":"AS12586","Network Name":"ASGHOSTNET GHOSTnet GmbH","Provider Family":"GHOSTnet","Country":"DE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Behavior-correlated enrollment infrastructure","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"eSentire observed final Intune enrollment from 5.230.71.51 on reported AS12586 after GhostCode device-code token theft. This is one incident and does not establish provider complicity.","Recommended Use":"Disabled by default. Alert on the exact IP or ASN only when correlated with device-code abuse, scripting user agents, token replay, or unexpected Intune/device enrollment.","Source IDs":"N48, N01"},{"ASN":"AS13317","Network Name":"AS-WAN - Wan holdings LLC","Provider Family":"","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"23.05","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #649 with 23.05% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS13332","Network Name":"HYPEENT-SJ - Hype Enterprises","Provider Family":"hypecreation.com","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"11.85","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #997 with 11.85% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS13335","Network Name":"CLOUDFLARENET - Cloudflare, Inc.","Provider Family":"Cloudflare","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Broad cloud/CDN control row","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N20, N01"},{"ASN":"AS13926","Network Name":"NETPROTECT-PHX - Strong Technology, LLC.","Provider Family":"Strong Technology / NetProtect","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Commercial VPN provider family expansion","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Active Strong Technology / NetProtect family ASN without sufficient direct campaign-time evidence for automatic monitoring. Disabled pending local need and validation.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N35, N36, N01"},{"ASN":"AS14618","Network Name":"AMAZON-AES - Amazon.com, Inc.","Provider Family":"Amazon Web Services","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Broad cloud/CDN control row","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N01"},{"ASN":"AS15012","Network Name":"TRIOLAB - NextStage Innovations LLC","Provider Family":"nextstageinnovations.com","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"25.78","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #613 with 25.78% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS15169","Network Name":"GOOGLE - Google LLC","Provider Family":"Google","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Broad cloud/CDN control row","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N01"},{"ASN":"AS16276","Network Name":"OVH OVH SAS","Provider Family":"OVHcloud","Country":"FR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Broad cloud provider with exact historical IOCs","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Two exact Proofpoint login-source IOCs historically originated from AS16276. OVH is a large shared cloud; keep the IP history but disable whole-ASN alerts by default.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S04, S06, N01"},{"ASN":"AS16509","Network Name":"AMAZON-02 - Amazon.com, Inc.","Provider Family":"Amazon Web Services","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Broad cloud/CDN control row","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N01"},{"ASN":"AS16625","Network Name":"AKAMAI-AS - Akamai Technologies, Inc.","Provider Family":"Akamai","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Broad cloud/CDN control row","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N01"},{"ASN":"AS17447","Network Name":"NET4-IN - Net4India Ltd","Provider Family":"net4india.com","Country":"IN","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"AS17447 is unannounced in current routing data and remains in live Spamhaus ASN-DROP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NET4-IN (net4india.com).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS17994","Network Name":"SPARK-AS-AP - Spark New Zealand Trading Ltd","Provider Family":"appserv.co.nz","Country":"NZ","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"This specific, currently unannounced ASN is in live Spamhaus ASN-DROP under appserv.co.nz. This finding does not apply to Spark New Zealand's other production ASNs. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SPARK-AS-AP (appserv.co.nz).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS20940","Network Name":"AKAMAI-ASN1 Akamai International B.V.","Provider Family":"Akamai","Country":"NL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Broad cloud/CDN control row","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N01"},{"ASN":"AS21308","Network Name":"ITMUA-AS Synapse Ukraine LLC","Provider Family":"synapse.net.ua","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.7","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #949 with 12.7% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS22781","Network Name":"STRTEC - Strong Technology, LLC.","Provider Family":"Strong Technology / NetProtect","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Commercial VPN provider family expansion","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Active Strong Technology / NetProtect family ASN without sufficient direct campaign-time evidence for automatic monitoring. Disabled pending local need and validation.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N35, N36, N01"},{"ASN":"AS24426","Network Name":"CNNIC-SINO-I - Beijing CE Huatong Information Technology Co., Ltd.","Provider Family":"myce.net.cn","Country":"CN","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"AS24426 is currently unannounced and present in live Spamhaus ASN-DROP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CNNIC-SINO-I (myce.net.cn).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS24567","Network Name":"QTINC-AS-AP - QT Inc.","Provider Family":"qtcloud.co.jp","Country":"JP","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"AS24567 is currently unannounced and present in live Spamhaus ASN-DROP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as QTINC-AS-AP (qtcloud.co.jp).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS25099","Network Name":"AS25099 PE NEO-CRAFT","Provider Family":"mozmail.com","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.45","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #856 with 14.45% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS25133","Network Name":"MCLAUT-AS LLC \"McLaut-Invest\"","Provider Family":"mclaut.com","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.34","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #964 with 12.34% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS25820","Network Name":"IT7NET - IT7 Networks Inc","Provider Family":"IT7 Networks Inc","Country":"CA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Point-IOC provider context","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Current origin of Kapibala C2 104.225.153.141. This supports source-scoped review, not provider-wide malicious attribution.","Recommended Use":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior.","Source IDs":"N39, N01"},{"ASN":"AS26561","Network Name":"NETRIDGE - NetRidge LLC","Provider Family":"mylir.co.uk","Country":"US","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"AS26561 is currently unannounced and present in live Spamhaus ASN-DROP under mylir.co.uk. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NETRIDGE (mylir.co.uk).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS27463","Network Name":"AS-GLOBALTELEHOST - GLOBALTELEHOST Corp.","Provider Family":"globaltelehost.com","Country":"CA","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Former ASN-DROP; non-originating lifecycle review","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Present in the 2026-09-15 ASN-DROP snapshot and absent from the 2026-09-29 snapshot; delisting does not establish benignness.","Recommended Use":"Disabled by default. Retain history and review current assignment, origin, and exact indicators before any enforcement.","Source IDs":"S01, S02, N01"},{"ASN":"AS27712","Network Name":"AS27712 - Paulo Dias de Araujo Filho","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"17","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #766 with 17% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS28111","Network Name":"AS28111 - Grupo Solunet SRL","Provider Family":"solunet.com.ar","Country":"AR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"16.03","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #795 with 16.03% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS29182","Network Name":"RU-JSCIOT JSC IOT","Provider Family":"","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Historical single-IP actor infrastructure","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"One short-lived Gamaredon C2 resolution was reported in this ASN. Preserve the exact IP only; do not enable ASN-wide monitoring without local evidence.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S08, N01"},{"ASN":"AS29233","Network Name":"IIP-NET-AS29233 Telecommunications center UMOS, LLC","Provider Family":"umos.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.09","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #918 with 13.09% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS30490","Network Name":"ETHRN - Ethr.Net LLC","Provider Family":"ethr.net","Country":"US","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"AS30490 is currently unannounced and present in live Spamhaus ASN-DROP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ETHRN (ethr.net).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS30823","Network Name":"AUROLOGIC aurologic GmbH","Provider Family":"combahton GmbH","Country":"DE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Legitimate upstream carrier, context only","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Recorded Future found aurologic to be a central upstream providing connectivity to many high-risk networks. The report expressly frames it as a legitimate carrier and does not establish aurologic itself as criminal or bulletproof hosting. Recorded Future's 2025 investigation identifies AS30823 as a central upstream and hosting nexus for multiple high-risk networks and suspected threat-activity enablers, including sanctioned Aeza infrastructure. The report expressly leaves negligence-versus-complicity unresolved and notes legitimate hosting/transit operations.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S05, X003, X031, N01"},{"ASN":"AS31345","Network Name":"MAGISTRAL2-AS Business Network Ltd","Provider Family":"bn.by","Country":"BY","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.48","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #753 with 17.48% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS31898","Network Name":"ORACLE-BMC-31898 - Oracle Corporation","Provider Family":"Oracle Cloud","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Broad cloud/CDN control row","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N01"},{"ASN":"AS33847","Network Name":"AE-ANKABUT Khalifa University","Provider Family":"ku.ac.ae","Country":"AE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse education review candidate","Abuse Band":"High","Abuse %":"15.63","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this education ASN #803 with 15.63% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS33923","Network Name":"ART-COM ART-COM Sp. z o.o.","Provider Family":"artcom.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the Very High band at rank #571 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS33991","Network Name":"IGRA-SERVICE-AS IGRA-SERVICE LLC","Provider Family":"g-service.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"11.92","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #989 with 11.92% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS34142","Network Name":"BARTA-AS LLC \"MicroTeam\"","Provider Family":"","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.06","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #873 with 14.06% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS34515","Network Name":"NextNet-AS Next Net for Internet and IT Services LTD","Provider Family":"nextnet.co","Country":"IQ","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"25.49","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #616 with 25.49% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS34582","Network Name":"VORONEZHSIGNAL-AS Voronezh-Signal LLC","Provider Family":"vsignal.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"12.5","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #953 with 12.5% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS35695","Network Name":"FALCON-AS F-NET sp. z o.o.","Provider Family":"f-net.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"15.43","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #810 with 15.43% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS36849","Network Name":"SAEOL-1-ASN - 1st Amendment Encrypted Openness LLC","Provider Family":"1aeo.com","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"98.29","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #466 with 98.29% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS38337","Network Name":"CNNIC-NTNet - NIU Telecommunications Inc","Provider Family":"niutelecom.com","Country":"CN","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CNNIC-NTNet (niutelecom.com).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS39297","Network Name":"ARTEFACT Prikarpatinserv LLC","Provider Family":"arte-fact.net","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.06","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #874 with 14.06% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS39361","Network Name":"YARCOM-AS Yarcom LLC","Provider Family":"","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.06","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #864 with 14.06% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS39577","Network Name":"GOODNET-AS Goodnet LLC","Provider Family":"gdnet.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"23.58","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #644 with 23.58% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS39690","Network Name":"OPSFOX-CLOUD DIGITAL NETWORK S.R.L.","Provider Family":"","Country":"MD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"","Abuse %":"","FP Risk":"N/A","Evidence Summary":"Current registry metadata assigns AS39690 to DIGITAL NETWORK S.R.L., but RIPEstat shows it is not announced. It is absent from the 2026-09-15 Spamhaus ASN-DROP snapshot, and no credible source-confirmed bulletproof-hosting or current campaign evidence was located.","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S05, N01"},{"ASN":"AS39720","Network Name":"MANILICH-AS Manilich Alla Valerievna","Provider Family":"darkclub.com.ua","Country":"UA","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as MANILICH-AS (darkclub.com.ua).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS39798","Network Name":"MivoCloud MivoCloud SRL","Provider Family":"","Country":"MD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Historical single-IP actor infrastructure","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"One short-lived Gamaredon C2 resolution was reported in this ASN. Preserve the exact IP only; do not enable ASN-wide monitoring without local evidence.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S08, N01"},{"ASN":"AS40665","Network Name":"SPCTR - SPECTRE NETWORKS LTD","Provider Family":"spectrenetworks.net","Country":"US","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SPCTR (spectrenetworks.net).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS40963","Network Name":"PRAID-AS DEMENIN B.V.","Provider Family":"bignet.ua","Country":"NL","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as PRAID-AS (bignet.ua).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS41171","Network Name":"Synergynet DIGITAL NETWORK S.R.L.","Provider Family":"","Country":"MD","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"","Abuse %":"","FP Risk":"N/A","Evidence Summary":"Current registry metadata assigns AS41171 to DIGITAL NETWORK S.R.L. under the Synergynet name, but RIPEstat shows no announcement. It is absent from the current Spamhaus ASN-DROP snapshot; no credible source-confirmed BPH or recent campaign association was located.","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S05, N01"},{"ASN":"AS41297","Network Name":"ABAKS-AS Adam Dlugosz trading as ABAKS","Provider Family":"abaks.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"47.38","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #526 with 47.38% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS41302","Network Name":"MART-AS KVS Ltd","Provider Family":"mart.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.68","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #952 with 12.68% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS42192","Network Name":"India THUNDER NETWORK LIMITED","Provider Family":"idodns.com","Country":"GB","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as India (idodns.com).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS42216","Network Name":"Netviser Bilisim Teknolojileri San. Ve T","Provider Family":"internetsahibi.net","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Current abuse-concentration hosting review candidate","Abuse Band":"High","Abuse %":"19.3","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this hosting ASN #702 with 19.3% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling.","Source IDs":"S03, N01"},{"ASN":"AS42419","Network Name":"TAVRIA-TRANSSERVIS-AS Tavria-TRANSSERVIS Ltd","Provider Family":"tavriatrans.com.ua","Country":"UA","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as TAVRIA-TRANSSERVIS-AS (tavriatrans.com.ua).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS42694","Network Name":"CONTRUST Elektrizitaetswerk Goesting V. Franz GmbH","Provider Family":"","Country":"AT","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Allocated but long-unannounced manual-review candidate","Abuse Band":"","Abuse %":"","FP Risk":"N/A","Evidence Summary":"Current RIPEstat metadata assigns AS42694 to the Austrian utility Elektrizitaetswerk Goesting V. Franz GmbH under CONTRUST and shows it unannounced. Older public ASN data recorded CYGATEGROUP-MALMO / Avinova AB, confirming identity churn. It is absent from current ASN-DROP, and no credible current abuse evidence was located.","Recommended Use":"Disabled pending fresh route visibility and current holder validation.","Source IDs":"S05, X029, N01"},{"ASN":"AS42881","Network Name":"Kontrast Contrust Solutions S.R.L.","Provider Family":"kontrast.md","Country":"MD","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Kontrast (kontrast.md).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS42969","Network Name":"ALPHASTRIKE Alpha Strike Labs GmbH","Provider Family":"alphastrike.io","Country":"DE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"66.15","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #484 with 66.15% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS43049","Network Name":"MULTISYSTEM-AS Multisystem Technologies Ltd.","Provider Family":"multisystem.net.ua","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.65","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #842 with 14.65% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS43094","Network Name":"Digital-Network DIGITAL NETWORK S.R.L.","Provider Family":"","Country":"MD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"","Abuse %":"","FP Risk":"N/A","Evidence Summary":"Current registry metadata assigns AS43094 to DIGITAL NETWORK S.R.L., while RIPEstat shows no route announcement. It is absent from current ASN-DROP. Public network directories classify the historic footprint as hosting/data-center space, but that is a business-type label, not evidence of malicious operation.","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S05, X033, N01"},{"ASN":"AS43273","Network Name":"OPTIKLINE-AS Optik Line LLC","Provider Family":"optikline.com","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"20.34","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #682 with 20.34% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS43420","Network Name":"ELTRONIK-AS Eltronik Sp. z o.o.","Provider Family":"eltronik.net.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"25.26","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #621 with 25.26% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS43530","Network Name":"IRTELCOM-AS Limited Liability Company Irtelcom","Provider Family":"irtelcom.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.06","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #765 with 17.06% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS43613","Network Name":"SOWA LLC BIGNET UKRAINE","Provider Family":"liptel.net.ua","Country":"UA","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as SOWA (liptel.net.ua).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS43764","Network Name":"SEVLUSH-AS LLC \"Electron-sevlush\"","Provider Family":"sevlush.net","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"23.64","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #642 with 23.64% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS43822","Network Name":"HOMEOPTIC HOMEOPTIC LLC","Provider Family":"homeoptic.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.87","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #884 with 13.87% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS43830","Network Name":"DIGITALENERGY-AS Basis LLC","Provider Family":"","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Historical single-IP actor infrastructure","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"One short-lived Gamaredon C2 resolution was reported in this ASN. Preserve the exact IP only; do not enable ASN-wide monitoring without local evidence.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S08, N01"},{"ASN":"AS44541","Network Name":"PRELUTION-AS Jochem Stobbe trading as Prelution","Provider Family":"prelution.nl","Country":"NL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"48.83","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #524 with 48.83% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS44589","Network Name":"NTservers DIGITAL NETWORK S.R.L.","Provider Family":"","Country":"MD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"High","Abuse %":"13.67","FP Risk":"N/A","Evidence Summary":"Current registry metadata assigns AS44589 to DIGITAL NETWORK S.R.L. and RIPEstat shows it unannounced. BGP.Tools likewise describes a network with no peers or upstreams. It is absent from the current Spamhaus ASN-DROP snapshot, and no source-confirmed BPH or current campaign evidence was located.","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S05, X039, N01, S03"},{"ASN":"AS44678","Network Name":"TVT-NET INKO Ltd.","Provider Family":"tvtk.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"16.64","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #777 with 16.64% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS44801","Network Name":"R-TEL-AS \"R-TEL\" LLC","Provider Family":"bignet.ua","Country":"UA","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as R-TEL-AS (bignet.ua).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS44834","Network Name":"POZITIVTELECOM-AS LLC \"POZITIV TELEKOM\"","Provider Family":"pozitivtelecom.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.89","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #932 with 12.89% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS45102","Network Name":"ALIBABA-CN-NET - Alibaba (US) Technology Co., Ltd.","Provider Family":"Alibaba Cloud","Country":"CN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Broad cloud/CDN control row","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N01"},{"ASN":"AS47105","Network Name":"as-vd Vault Dweller OU","Provider Family":"vaultdweller.net","Country":"EE","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"Present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Spamhaus says ASN-DROP entries are ASNs hijacked or leased by professional spam/cybercrime operations and used for malware, botnet control and related abuse, with no legitimate traffic. RIPEstat currently shows no route announcement, so it is operationally dormant despite the live reputation entry. The feed does not say whether this specific entry is hijacked, leased, or operated by a bulletproof host, so it is source-confirmed malicious infrastructure but not proof that the registry-named holder knowingly runs BPH. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as as-vd (vaultdweller.net).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS47154","Network Name":"HUSAM-Network HUSAM A. H. HIJAZI","Provider Family":"as49870.net","Country":"PS","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"62.5","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #487 with 62.5% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS47204","Network Name":"MCS-AS MCS LLC","Provider Family":"mcs.ooo","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"23.93","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #636 with 23.93% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS47288","Network Name":"FIXNET FIXNET Telekomunikasyon Limited Sirketi","Provider Family":"fixnet.com.tr","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"11.89","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #995 with 11.89% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS47329","Network Name":"WDM-AS WDM Sp. z o.o.","Provider Family":"wdm.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"61.93","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #488 with 61.93% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS47397","Network Name":"BASE-AS Base Ltd.","Provider Family":"base-net.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.87","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #833 with 14.87% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS47500","Network Name":"www-networkpolice-org SC ITNS.NET SRL","Provider Family":"","Country":"MD","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Allocated but long-unannounced manual-review candidate","Abuse Band":"","Abuse %":"","FP Risk":"N/A","Evidence Summary":"Current registry metadata assigns AS47500 to SC ITNS.NET SRL under www-networkpolice-org, but RIPEstat shows it unannounced. It is absent from current Spamhaus ASN-DROP, and no credible source-confirmed BPH or recent campaign evidence was located.","Recommended Use":"Disabled pending fresh route visibility and current holder validation.","Source IDs":"S05, X044, N01"},{"ASN":"AS47551","Network Name":"AS-MAYAK-NETWORK \"MAYAK NETWORK\" LLC","Provider Family":"mayaknet.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.3","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #967 with 12.3% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS47860","Network Name":"OTC-AS OOO \"OTC\"","Provider Family":"bsh.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"12.3","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #965 with 12.3% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS48120","Network Name":"FLASHTELECOM-AS Flash Telecom LLC","Provider Family":"flash-telecom.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"23.44","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #645 with 23.44% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS48162","Network Name":"VYSHKOVO-AS Bihunets Ishtvan Stepanovych","Provider Family":"","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"18.36","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #728 with 18.36% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS48433","Network Name":"OMIPLAT-AS Omiplat LLC","Provider Family":"omiplat.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"12.79","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #942 with 12.79% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS48494","Network Name":"MKNET-AS BUKO LTD","Provider Family":"mknet.biz","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.36","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #758 with 17.36% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS48525","Network Name":"UZUMBANK-AS JSC Uzum Bank","Provider Family":"uzumbank.uz","Country":"UZ","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse banking review candidate","Abuse Band":"High","Abuse %":"19.14","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this banking ASN #710 with 19.14% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS48974","Network Name":"Digital-Network DIGITAL NETWORK S.R.L.","Provider Family":"","Country":"MD","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"","Abuse %":"","FP Risk":"N/A","Evidence Summary":"RIPEstat reports AS48974 as not currently announced. It is not in the current Spamhaus ASN-DROP snapshot, and no strong current BPH designation was found during this review.","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S05, N01"},{"ASN":"AS48995","Network Name":"NOVLINE-AS IE Gilaskhanov Said Visirpashaevich","Provider Family":"","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"15.23","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #816 with 15.23% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS49006","Network Name":"Systems SC ITNS.NET SRL","Provider Family":"","Country":"MD","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Allocated but long-unannounced manual-review candidate","Abuse Band":"","Abuse %":"","FP Risk":"N/A","Evidence Summary":"RIPEstat reports AS49006 as not currently announced. It is absent from the current Spamhaus ASN-DROP snapshot, and no strong current BPH evidence was identified.","Recommended Use":"Disabled pending fresh route visibility and current holder validation.","Source IDs":"S05, N01"},{"ASN":"AS49399","Network Name":"ESAB-2-AS 31173 Services AB","Provider Family":"31173.se","Country":"SE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"17.19","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #762 with 17.19% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS49443","Network Name":"Contrust-Solutions Contrust Solutions S.R.L.","Provider Family":"kontrast.md","Country":"MD","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"AS49443 remains in the current Spamhaus ASN-DROP snapshot, but RIPEstat reports it as not currently announced. Retain the high-risk label and watch for reannouncement rather than generating routine active alerts. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Contrust-Solutions (kontrast.md).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS49468","Network Name":"MAGHOST_RO MAGIT'ST SRL","Provider Family":"MAGIT'ST SRL","Country":"RO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Conditional fast-flux ASN seed","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Conditional fast-flux analytic includes this ASN. This supports source-scoped review, not provider-wide malicious attribution.","Recommended Use":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior.","Source IDs":"N38, N01"},{"ASN":"AS49588","Network Name":"SlvNet-as SDS-Vostok Ltd.","Provider Family":"slv.net.ua","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"12.69","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #951 with 12.69% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS49755","Network Name":"telecom-159-ru LLC SvyazTelecom","Provider Family":"159.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"15.23","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #820 with 15.23% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS49785","Network Name":"AWIST P.P.H.U AWIST","Provider Family":"inetia.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"33.98","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #560 with 33.98% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS49840","Network Name":"XREALNET Enson Net Ltd","Provider Family":"ensonnet.com","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"18.12","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #733 with 18.12% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS49854","Network Name":"STARLINKCOUNTRY-AS Starlink Country LLC","Provider Family":"levokumka.net","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.97","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #735 with 17.97% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS50015","Network Name":"HOLINET-AS Aleksandr Butenko","Provider Family":"","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.37","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #962 with 12.37% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS50138","Network Name":"CTC-ALFA-AS Centrul Tehnic Comercial Alfa SA","Provider Family":"","Country":"MD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Legacy hosting/VPS watchlist","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"RIPEstat currently sees AS50138 announced. Public provider and Moldovan regulator material identify Alfa as an internet access provider. It is not in the current Spamhaus ASN-DROP snapshot, and no strong current BPH designation was found.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S05, X051, N01"},{"ASN":"AS50174","Network Name":"INTEXCOM-AS Intexcom OOO","Provider Family":"intexcom.net","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.18","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #913 with 13.18% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS50236","Network Name":"Vertexlink_Communications VertexLink Inc.","Provider Family":"62yun.com","Country":"US","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"AS50236 is present in the current Spamhaus ASN-DROP snapshot, but RIPEstat reports it as not currently announced. The registry country and Spamhaus country labels differ, reinforcing that country fields should not be used for actor attribution. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Vertexlink_Communications (62yun.com).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS50308","Network Name":"FREE50308 Address Limited","Provider Family":"","Country":"HK","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Allocated but long-unannounced manual-review candidate","Abuse Band":"","Abuse %":"","FP Risk":"N/A","Evidence Summary":"RIPEstat reports AS50308 as not currently announced. It is absent from current Spamhaus ASN-DROP and no strong current BPH evidence was identified.","Recommended Use":"Disabled pending fresh route visibility and current holder validation.","Source IDs":"S05, N01"},{"ASN":"AS50467","Network Name":"BESKID-MEDIA-AS Beskid Media Sp. z o.o.","Provider Family":"beskidmedia.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.87","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #881 with 13.87% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS50935","Network Name":"International-Hosting-Solutions-AS INTERNATIONAL HOSTING SOLUTIONS LLP","Provider Family":"","Country":"GB","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Allocated but long-unannounced manual-review candidate","Abuse Band":"","Abuse %":"","FP Risk":"N/A","Evidence Summary":"RIPEstat reports AS50935 as not currently announced. It is not in the current Spamhaus ASN-DROP snapshot, and no strong current BPH designation was found.","Recommended Use":"Disabled pending fresh route visibility and current holder validation.","Source IDs":"S05, N01"},{"ASN":"AS51045","Network Name":"DEMENIN-AS DEMENIN B.V.","Provider Family":"bignet.ua","Country":"NL","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"AS51045 remains in the current Spamhaus ASN-DROP snapshot under bignet.ua, but RIPEstat reports it as not currently announced. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as DEMENIN-AS (bignet.ua).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS51104","Network Name":"Remini-Telecom VIP GROUP (S.A.R.L)","Provider Family":"","Country":"LB","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"15.36","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #811 with 15.36% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS51246","Network Name":"RASVTV RASV-TV SRL","Provider Family":"","Country":"MD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Legacy hosting/VPS watchlist","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"RIPEstat currently sees AS51246 announced. RASV-TV describes itself as a local cable internet and digital television provider. It is not in current Spamhaus ASN-DROP and no strong current BPH designation was found.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S05, X052, N01"},{"ASN":"AS51381","Network Name":"ELITETEAM-PEERING-AZ1 1337TEAM LIMITED","Provider Family":"ELITETEAM / 1337TEAM","Country":"SC","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"Team Cymru identified ELITETEAM/1337TEAM as a bulletproof hosting provider and associated AS51381 with its infrastructure. AS51381 remains in current Spamhaus ASN-DROP, but RIPEstat reports no current announcement. Team Cymru linked four ASNs to ELITETEAM/1337TEAM. AS56873 and AS51381 remain in current ASN-DROP even though current RIPEstat enrichment reports them unannounced; AS39770 and AS60424 are historical/unannounced. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ELITETEAM-PEERING-AZ1 (eliteteam.to).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, S16, N01, S03"},{"ASN":"AS51488","Network Name":"GARANTTELESETI-AS Garant-Teleseti LLC","Provider Family":"aogarant.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"19.14","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #709 with 19.14% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS52008","Network Name":"NESTER-NET NesterTelecom LLC","Provider Family":"nester.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"71.43","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #478 with 71.43% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS52045","Network Name":"VIZIT-AS PTRC-VIZIT","Provider Family":"","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"18.36","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #729 with 18.36% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS52490","Network Name":"AS52490 - COOPERATIVA DE ELECTRICIDAD DE PEDRO LURO","Provider Family":"","Country":"AR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"38.13","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #545 with 38.13% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS52543","Network Name":"AS52543 - ATL Comercio e Servicos de Informatica Ltda","Provider Family":"microsattelecom.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.93","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #877 with 13.93% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS52630","Network Name":"AS52630 - MOTTANET TI - SERVICOS DE TECNOLOGIA DA INFO","Provider Family":"mottanet.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"25.39","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #618 with 25.39% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS52635","Network Name":"AS52635 - SPEEDCONNECT - TECNOLOGIA E EQUIPAMENTOS","Provider Family":"speedconnectfibra.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.09","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #919 with 13.09% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS52688","Network Name":"AS52688 - FATIMA VIDEO ELETRONICA LTDA ME","Provider Family":"fatimavideo.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"33.33","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #567 with 33.33% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS52780","Network Name":"AS52780 - MAP Piumhi Ltda - ME","Provider Family":"mapminas.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"49.17","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #521 with 49.17% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS52904","Network Name":"AS52904 - Multpontos Telecomunicacoes Ltda - ME","Provider Family":"multpontos.net.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"21.74","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #664 with 21.74% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS52937","Network Name":"AS52937 - FHP TELECOMUNICACAO E COM VAREJISTA DE PRODUTOS DE","Provider Family":"fhpfibra.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"16.7","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #775 with 16.7% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS53003","Network Name":"AS53003 - EVOLUNET PROVEDORA DE INTERNET LTDA PE","Provider Family":"evolunetcorp.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.38","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #757 with 17.38% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS53072","Network Name":"AS53072 - INETVIP TELECOM LTDA","Provider Family":"inetvip.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"21.21","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #672 with 21.21% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS53158","Network Name":"AS53158 - Net Turbo Telecom","Provider Family":"netturbo.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"67.12","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #479 with 67.12% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS54113","Network Name":"FASTLY - Fastly, Inc.","Provider Family":"Fastly","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Broad cloud/CDN control row","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N01"},{"ASN":"AS55748","Network Name":"MORSE-JP - 7-9-10 Nishi-Shinjuku","Provider Family":"morsejp.com","Country":"JP","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"AS55748 remains in current Spamhaus ASN-DROP, but RIPEstat reports it as not currently announced. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as MORSE-JP (morsejp.com).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS56268","Network Name":"SREERAM-NED1-IN - Northeast Dataa Network Pvt Ltd","Provider Family":"nedataa.com","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"21.51","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #669 with 21.51% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS56291","Network Name":"ACE-AS-AP - Ace, Inc.","Provider Family":"ace-idc.com","Country":"JP","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"AS56291 is in the current Spamhaus ASN-DROP snapshot, but RIPEstat reports it as not currently announced. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ACE-AS-AP (ace-idc.com).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, N01, S03"},{"ASN":"AS56400","Network Name":"ASSPDChernega SPD Chernega Aleksandr Anatolevich","Provider Family":"flycom.net.ua","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.95","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #876 with 13.95% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS56541","Network Name":"KOMETA-AS KOMETA LLC","Provider Family":"pinspb.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.92","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #878 with 13.92% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS56606","Network Name":"NERACOM-AS NERACOM Ltd.","Provider Family":"neracom.bg","Country":"BG","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.06","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #866 with 14.06% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS56812","Network Name":"ASZARKO CHP Zarko Alexandr Ivanovich","Provider Family":"komsomolske.net","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"20.34","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #683 with 20.34% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS56873","Network Name":"ELITETEAM-ANTIDDOS 1337TEAM LIMITED","Provider Family":"ELITETEAM / 1337TEAM","Country":"SC","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"Team Cymru identified ELITETEAM/1337TEAM as a bulletproof hosting provider and associated AS56873 with its infrastructure. The ASN remains in current Spamhaus ASN-DROP, but RIPEstat reports no current announcement. Team Cymru linked four ASNs to ELITETEAM/1337TEAM. AS56873 and AS51381 remain in current ASN-DROP even though current RIPEstat enrichment reports them unannounced; AS39770 and AS60424 are historical/unannounced. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as ELITETEAM-ANTIDDOS (eliteteam.to).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, S16, N01, S03"},{"ASN":"AS56985","Network Name":"RUSTEL-AS RUSTEL LLC","Provider Family":"telsto.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.89","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #925 with 12.89% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS57013","Network Name":"EURASIA-STAR-AS Eurasia-Star LLP","Provider Family":"esnet.kz","Country":"KZ","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"20.61","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #679 with 20.61% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS57403","Network Name":"HAZI HFM S.R.L","Provider Family":"hazi.ro","Country":"RO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"16.6","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #780 with 16.6% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS57411","Network Name":"NOVOTEHNIKS-AS Novotehniks LLC","Provider Family":"ntx55.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"21.88","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #663 with 21.88% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS57523","Network Name":"changway-as Chang Way Technologies Co. Limited","Provider Family":"Chang Way Technologies","Country":"HK","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"Recorded Future's 2022 report explicitly named Chang Way Technologies as a known BPH provider and mapped AS57523 to it. Spamhaus still lists the ASN in its 2026-09-15 ASN-DROP snapshot, but it is not currently announcing routes. Recorded Future's 2022 adversary-infrastructure report listed AS57523 among networks observed hosting Cobalt Strike. It remains in current Spamhaus ASN-DROP, but RIPEstat reports it as not currently announced. This is infrastructure evidence, not nationality attribution. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as changway-as (changway.hk).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, S05, X057, N01, S03"},{"ASN":"AS57558","Network Name":"METIS-AS METIS S.R.L.","Provider Family":"metissrl.it","Country":"IT","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"29.3","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #586 with 29.3% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS57789","Network Name":"HOMENET HomeNet Technologies Sp. z o.o.","Provider Family":"home-net.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"28.95","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #588 with 28.95% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS57916","Network Name":"LAROM-AS Larom TV SRL","Provider Family":"","Country":"MD","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Allocated but long-unannounced manual-review candidate","Abuse Band":"","Abuse %":"","FP Risk":"N/A","Evidence Summary":"RIPEstat reports AS57916 as not currently announced. It is absent from current Spamhaus ASN-DROP and no strong current BPH designation was found.","Recommended Use":"Disabled pending fresh route visibility and current holder validation.","Source IDs":"S05, N01"},{"ASN":"AS58070","Network Name":"KSN-AS Kriukov Sergei Nikolaevich","Provider Family":"","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"13.28","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #905 with 13.28% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS58087","Network Name":"FlorianKolb Florian Kolb","Provider Family":"datalix.de","Country":"DE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"14.96","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #832 with 14.96% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS58347","Network Name":"AIK-AS AiK LLC","Provider Family":"gwave.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"26.3","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #611 with 26.3% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS58401","Network Name":"XROUTE-AS-ID - PT. DEWATA TELEMATIKA","Provider Family":"detelnetworks.id","Country":"ID","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.11","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #979 with 12.11% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS58427","Network Name":"GEC-AF - Global Entourage Services","Provider Family":"gec.af","Country":"AF","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.77","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #837 with 14.77% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS59392","Network Name":"FLASH-INTERNET-AS IE Valevskaya Elena Evgenevna","Provider Family":"","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #968 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS59574","Network Name":"AS-STUPINO-NET Limited Liability Company SKS Telecom","Provider Family":"stupino.net","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.78","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #887 with 13.78% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS59847","Network Name":"WIRAC WIRAC.NET d.o.o.","Provider Family":"wirac.ba","Country":"BA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #999 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS60005","Network Name":"IT-service-AS IT-service LLC","Provider Family":"","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.45","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #855 with 14.45% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS60017","Network Name":"FASTLINES FASTLINES SRL","Provider Family":"fastlines.it","Country":"IT","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"19.34","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #700 with 19.34% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS60246","Network Name":"PG-19 Consumer Internet Cooperative PG-19","Provider Family":"pg19.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"11.89","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #994 with 11.89% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS60286","Network Name":"STEPNET-KZ-AS Agency-KA Ltd.","Provider Family":"stepnet.kz","Country":"KZ","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"15.16","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #826 with 15.16% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS60729","Network Name":"TORSERVERS-NET Stiftung Erneuerbare Freiheit","Provider Family":"renewablefreedom.org","Country":"DE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"60.81","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #491 with 60.81% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS61367","Network Name":"ASBALKHASH TOO \"B-TEL\"","Provider Family":"71036.kz","Country":"KZ","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.89","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #879 with 13.89% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS61748","Network Name":"AS61748 - Dkirosnet Servicos de Internet","Provider Family":"d-kiros.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"24.15","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #633 with 24.15% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS61756","Network Name":"AS61756 - NETPONTAL PROVEDOR DE INTERNET LTDA - ME","Provider Family":"netpontal.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"50","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #514 with 50% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS61782","Network Name":"AS61782 - WNNet Telecom","Provider Family":"wnnet.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"33.33","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #569 with 33.33% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS61851","Network Name":"AS61851 - Garra Fibra","Provider Family":"garratelecom.net.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"33.56","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #561 with 33.56% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS63179","Network Name":"TWITTER - Twitter Inc.","Provider Family":"x.com","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"21.11","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #673 with 21.11% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS64429","Network Name":"OPTIKNET-AS DDS Service LLC","Provider Family":"optiknet.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"31.03","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #579 with 31.03% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS132073","Network Name":"WAVENET-AS-AP - Wave Net","Provider Family":"wave-net.pl","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #975 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS132206","Network Name":"DATAHUB-VN - DC DIGITAL DATA HUB COMPANY LIMITED","Provider Family":"datahub.vn","Country":"VN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"99.41","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #461 with 99.41% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS132438","Network Name":"APONIT-AS-AP - Evan Ahmed Bhuiyan t/a APON IT","Provider Family":"aponit.com","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.18","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #914 with 13.18% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS132934","Network Name":"SKYMAX-AS - Skymax Broadband Services Pvt. Ltd.","Provider Family":"apjii.or.id","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.34","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #900 with 13.34% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS134299","Network Name":"GSTECH-AS - Gstech Software Systems Pvt Ltd","Provider Family":"preciousnetcom.in","Country":"IN","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the Very High band at rank #545 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS135488","Network Name":"IDNIC-OTHMARNETWORK-AS-ID - PT OTHMAR MATRA MEDIA","Provider Family":"othmarnetwork.com","Country":"ID","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"16.8","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #771 with 16.8% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS135683","Network Name":"NETNCR-AS - Netncr Technology Pvt. Ltd.","Provider Family":"netncr.com","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"12.01","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #985 with 12.01% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS135765","Network Name":"WEBMAX33-AS-IN - WEBMAX NETWORK SOLUTIONS PRIVATE LIMITED","Provider Family":"webmaxnet.com","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"18.95","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #712 with 18.95% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS135815","Network Name":"NETREXO-AS - Netrexo Communications Private Limited","Provider Family":"netrexo.com","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"15.53","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #809 with 15.53% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS135818","Network Name":"GTNCPL-AS - Green Tech Net Com Pvt Ltd","Provider Family":"gtncpl.com","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"16.6","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #779 with 16.6% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS135850","Network Name":"NSNPLMRJ-AS - Net Sathi Networks Pvt. Ltd","Provider Family":"apjii.or.id","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"20.12","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #688 with 20.12% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS135915","Network Name":"TLSOFT-AS-VN - 8 Floor, 96-98 Dao Duy Anh, Phu Nhuan, HCMC","Provider Family":"tlsoft.vn","Country":"VN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"33.5","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #562 with 33.5% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS135981","Network Name":"VISUALVIET-AS-VN - VisualViet Company Limited","Provider Family":"apjii.or.id","Country":"VN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"12.24","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #969 with 12.24% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS136319","Network Name":"APLL-AS-IN - Acebrowse Private Ltd","Provider Family":"acebrowse.com","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"21.58","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #666 with 21.58% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS136676","Network Name":"KADSYSCON-AS - Kad-syscon Infotech Private Limited","Provider Family":"apjii.or.id","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"15.82","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #798 with 15.82% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS136879","Network Name":"JARINDO-AS-ID - DELAPAN BIT","Provider Family":"jarindo.id","Country":"ID","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"16.93","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #768 with 16.93% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS138183","Network Name":"MSCOMPUTERMATE-AS-AP - Computer Mate","Provider Family":"computermate.net","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.28","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #907 with 13.28% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS138655","Network Name":"TES-PL-AS-AP - Trans World Enterprise Services (Private) Limited","Provider Family":"tes.com.pk","Country":"PK","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #907 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS138953","Network Name":"TOPNETWORK-AS-AP - Top Network","Provider Family":"topnetbd.com","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"20.31","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #684 with 20.31% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS138992","Network Name":"AYSHAITSOLUTIONS-AS-AP - Aysha IT Solutions","Provider Family":"ayshait.net","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #989 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS139202","Network Name":"POWERMEDIA-AS-AP - Power Media","Provider Family":"powermediabd.net","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.97","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #736 with 17.97% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS139347","Network Name":"RVCYBERWORLD-AS-AP - Md Masud Rana Roni t/a RV Cyber World","Provider Family":"rvcyberworld.net","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"15.63","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #805 with 15.63% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS139381","Network Name":"IDNIC-CITRA-BERDIKARI-NUSANTARA-AS-ID - PT.CITRA BERDIKARI NUSANTARA","Provider Family":"citraberdikari.co.id","Country":"ID","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"20.12","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #689 with 20.12% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS139549","Network Name":"CRISPENT-AS - Crisp Enterprises","Provider Family":"apjii.or.id","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"16.54","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #781 with 16.54% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS139678","Network Name":"JOYDEBPUR-AS-AP - Joydebpur Network","Provider Family":"joydebpurnetwork.net","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.28","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #909 with 13.28% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS139718","Network Name":"TORNADO3-AS-AP - Tornado Networks (Pvt.) Limited","Provider Family":"tornado.com.pk","Country":"PK","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"26.95","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #604 with 26.95% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS139728","Network Name":"P3C-AS-AP - Planet Three Communication","Provider Family":"planet3communication.com","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.11","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #980 with 12.11% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS139779","Network Name":"NHB2-AS-AP - Net@Home-Bamoul Branch","Provider Family":"netathomebd.net","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #988 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS139839","Network Name":"ZERONET-AS-AP - ZeroNET","Provider Family":"zeronetbd.net","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"19.14","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #706 with 19.14% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS139879","Network Name":"GALAXY-AS-AP - Galaxy Broadband","Provider Family":"galaxy.net.pk","Country":"PK","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.81","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #941 with 12.81% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS140026","Network Name":"TIMORNET-AS-ID - PT. KUPANG INTERMEDIA","Provider Family":"timornet.id","Country":"ID","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"39.39","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #541 with 39.39% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS140210","Network Name":"CONNECTX-AS-AP - ConnectX","Provider Family":"connectx.pk","Country":"PK","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.11","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #981 with 12.11% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS140807","Network Name":"TND-AS-VN - Nguyen Ngoc Thanh Trading Limited Company","Provider Family":"tnd.vn","Country":"VN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"21.56","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #667 with 21.56% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS140906","Network Name":"MAYASOFT-AS-AP - MAYA SOFT","Provider Family":"mayasoftbd.net","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"14.06","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #869 with 14.06% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS140923","Network Name":"GLOBALLINK-AS-AP - Global Link","Provider Family":"globallinkbd.net","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"39.06","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #542 with 39.06% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS140952","Network Name":"STL-AS-AP - Strong Technology, LLC","Provider Family":"Strong Technology / NetProtect","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Commercial VPN provider family expansion","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Active Strong Technology / NetProtect family ASN without sufficient direct campaign-time evidence for automatic monitoring. Disabled pending local need and validation.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N35, N36, N01"},{"ASN":"AS141098","Network Name":"MULTIMEDIALINKTECH-AS-ID - PT Multimedia Link Technology","Provider Family":"multimedialinktech.net","Country":"ID","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #974 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS141127","Network Name":"IDNIC-CDNNET-AS-ID - PT Anugerah Cimanuk Raya","Provider Family":"","Country":"ID","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.17","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #973 with 12.17% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS141295","Network Name":"MAPIT-AS-IN - Madhya Pradesh Agency For Promotion Of Information Technology","Provider Family":"mapit.gov.in","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse government review candidate","Abuse Band":"High","Abuse %":"15.23","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this government ASN #817 with 15.23% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS141347","Network Name":"M7STL-AS-AP - 7 Star Telecom (Private) Limited","Provider Family":"7startelecom.net","Country":"PK","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"24.61","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #629 with 24.61% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS141536","Network Name":"INTERLOK-AS-IN - Interlock Communication","Provider Family":"","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.26","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #860 with 14.26% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS141642","Network Name":"IDNIC-RINGNET-AS-ID - PT Ring Media Nusantara","Provider Family":"ring.net.id","Country":"ID","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #928 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS141737","Network Name":"RAPIDNETWORK-AS-AP - Rapid Network","Provider Family":"rapidnetworkbd.com","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"21.48","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #670 with 21.48% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS141787","Network Name":"LINKOTEK-AS - LINKOTEK NETWORK PRIVATE LIMITED","Provider Family":"linkotek.in","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"29.69","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #585 with 29.69% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS141870","Network Name":"GVREDDY-AS-IN - GV REDDY BROADBAND SERVICES","Provider Family":"","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"23.05","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #651 with 23.05% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS141874","Network Name":"DISHACR2-AS-IN - DISHA INFOCARE","Provider Family":"","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"17.38","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #756 with 17.38% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS142015","Network Name":"FOXPROTECHNOLOGY-AS-AP - Foxpro Technology","Provider Family":"foxpro.com.bd","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"23.05","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #650 with 23.05% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS142352","Network Name":"IDNIC-TAHTA-ID - PT. PRATAMA HASTA UTAMA SOLUSINDO","Provider Family":"tahtasolusindo.id","Country":"ID","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.58","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #750 with 17.58% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS142627","Network Name":"MULTILINK-AS-AP - Multilink International","Provider Family":"multilinkisp.com","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.77","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #745 with 17.77% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS142647","Network Name":"NAN-AS-AP - Nasstec Airnet Networks Private Limited","Provider Family":"nasstecairnet.net.pk","Country":"PK","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #906 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS147006","Network Name":"STARIT-AS-AP - Star IT","Provider Family":"staritisp.com","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.97","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #738 with 17.97% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS149179","Network Name":"NET6-AS-AP - Net Express","Provider Family":"netexpress.info","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"42.97","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #534 with 42.97% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS149270","Network Name":"LUCKYNET2-AS-IN - Lucky Internet Services Pvt Ltd","Provider Family":"luckyisp.in","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"24.41","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #630 with 24.41% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS149561","Network Name":"NBPLRAJ-AS-IN - 777 Network Broadband Private Limited","Provider Family":"777network.net","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"21.88","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #661 with 21.88% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS149638","Network Name":"ELMAMULTIMEDIA-AS-AP - Elma Multimedia","Provider Family":"elmamultimedia.com","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #990 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS149653","Network Name":"FAISAL-AS-AP - Faisal Network","Provider Family":"faisalnetwork.net","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.65","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #843 with 14.65% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS149877","Network Name":"IJE-AS-ID - PT Integrasi Jaringan Ekosistem","Provider Family":"weave.co.id","Country":"ID","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"22.49","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #658 with 22.49% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS149878","Network Name":"IDNIC-CTSOLUSINDO-AS-ID - PT Callysta Total Solusindo","Provider Family":"ctsolusindo.co.id","Country":"ID","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"12.3","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #966 with 12.3% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS150170","Network Name":"WEBELEVEN-AS-AP - Web Eleven","Provider Family":"web-eleven.com","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.28","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #908 with 13.28% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS150493","Network Name":"IDNIC-PGSS-AS-ID - PT Gunung Sedayu Sentosa","Provider Family":"gss.biz.id","Country":"ID","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"21.88","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #660 with 21.88% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS150747","Network Name":"HIRAELECTRONICSANDN-AS-AP - Hire Electronic & Networking","Provider Family":"hiraelectronicsandnetworking.com","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.5","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #955 with 12.5% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS150884","Network Name":"NEWVINA-VN - ANZIX Joint Stock Company","Provider Family":"apjii.or.id","Country":"VN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #851 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS151148","Network Name":"TELESAR-AS - Sar Network","Provider Family":"apjii.or.id","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"28.52","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #592 with 28.52% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS151595","Network Name":"IDNIC-MERDEKANET-AS-ID - PT Merdeka Media Teknologi","Provider Family":"merdekanet.co.id","Country":"ID","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.45","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #851 with 14.45% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS151741","Network Name":"VORTEX1-AS-IN - VORTEX NETWORKS PRIVATE LIMITED","Provider Family":"vortexnetworks.in","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"16.99","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #767 with 16.99% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS153016","Network Name":"CHANGEDIGITAL-VN - VN Change Digital Ltd.","Provider Family":"apjii.or.id","Country":"VN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"16.41","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #788 with 16.41% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS153236","Network Name":"V3CONECT-AS-IN - KARNATAKA FASTNET PRIVATE LIMITED","Provider Family":"ind.in","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.28","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #906 with 13.28% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS153307","Network Name":"BOS-AS-AP - Bangladesh Online Service","Provider Family":"bdos.info","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #976 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS153337","Network Name":"NETRELATION-AS-AP - Net Relation","Provider Family":"netrelationbd.com","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"32.81","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #571 with 32.81% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS153490","Network Name":"DATALINKPLC-AS-AP - DataLink","Provider Family":"datalink.com.bd","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"19.92","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #691 with 19.92% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS153844","Network Name":"RNBL-AS-AP - Riderz Network Broadband (Private) Limited","Provider Family":"riderz.pk","Country":"PK","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #980 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS154247","Network Name":"MCO-VN - MCO HA NOI TECHNOLOGY COMPANY LIMITED","Provider Family":"topserver.vn","Country":"VN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #166 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS154455","Network Name":"IRINN-AYUSMATI-AS-IN - AYUSHMATI LOGITECH PRIVATE LIMITED","Provider Family":"","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.67","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #890 with 13.67% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS154650","Network Name":"IRINN-SKYAERO-AS-IN - SKYAERO PRIVATE LIMITED","Provider Family":"","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse unknown review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #991 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS154676","Network Name":"EFTETRADINGCORPORATIONLTD-AS-BD - Efte Trading Corporation Ltd","Provider Family":"cloudview.com.bd","Country":"BD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"34.77","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #557 with 34.77% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS196629","Network Name":"DOMINION-AS Antipov Oleg","Provider Family":"dominion.ru.net","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"22.85","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #652 with 22.85% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS196767","Network Name":"INMART1-AS INMART.UA LLC","Provider Family":"inmart.net.ua","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.91","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #742 with 17.91% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS196786","Network Name":"ASMITEL IP Yashutkin Andrei Vladimirovich","Provider Family":"mitel-inter.net","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"14.43","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #858 with 14.43% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS196865","Network Name":"AIRCOMM Aircomm S.r.L.","Provider Family":"aircomm.it","Country":"IT","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"11.97","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #987 with 11.97% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS196886","Network Name":"Orion-Telekom-Korisnici-AS Orion Telekom Tim d.o.o.Beograd","Provider Family":"oriontelekom.rs","Country":"RS","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"16.41","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #791 with 16.41% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS197052","Network Name":"YANKOVSKIY-AS Yankovskiy Nikolay Nikolayevich","Provider Family":"westcall.spb.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"14.06","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #867 with 14.06% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS197218","Network Name":"ASLANPRO PP Dmutrashko Evgeny Vitalievich","Provider Family":"","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"45.12","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #529 with 45.12% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS197574","Network Name":"EXPRESSHOST ExpressHost Ltd","Provider Family":"ExpressHost Ltd","Country":"GB","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Conditional fast-flux ASN seed","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Conditional fast-flux analytic includes this ASN. This supports source-scoped review, not provider-wide malicious attribution.","Recommended Use":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior.","Source IDs":"N38, N01"},{"ASN":"AS197578","Network Name":"Alekseenko-NET PE Alekseenko Igor Yurevich","Provider Family":"pautina-net.ru","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"15.63","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #804 with 15.63% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS197620","Network Name":"EZ-BIT-AS ezbit sp. z o.o.","Provider Family":"ezbit.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.26","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #968 with 12.26% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS197697","Network Name":"PL-LUB-DERKOM-AS Dariusz Klimczuk trading as DERKOM Sp. J.","Provider Family":"derkom.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"27.27","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #602 with 27.27% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS197714","Network Name":"CITYLINE-RU Chishko Evgeniy Nikolaevich","Provider Family":"","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.48","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #898 with 13.48% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS197793","Network Name":"GIGABIT-NET Gigabit LLC","Provider Family":"ggbt.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"18.75","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #718 with 18.75% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS197835","Network Name":"FUSOLAB FUSOLAB APS E ASD","Provider Family":"ninux.org","Country":"IT","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"13.28","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #912 with 13.28% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS197868","Network Name":"ServiceTelecom LLC Service Telecom","Provider Family":"service-net.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.7","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #947 with 12.7% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS197893","Network Name":"ELSUHD-AS Elsuhd Company for Communications Services, Cybersecurity, Information Technology, Electronic Governance, and Commercial Agencies, Ltd.","Provider Family":"elsuhdnet.com","Country":"IQ","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"19.14","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #708 with 19.14% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS197960","Network Name":"MEGANET LIMITED LIABILITY COMPANY \"INTERNET SERVICE PROVIDER \"MEGA\"","Provider Family":"mega.net.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"21.03","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #676 with 21.03% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS198075","Network Name":"BOUNCEZERO-MNT BounceZero Ltd","Provider Family":"bouncezero.io","Country":"GB","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"42.58","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #535 with 42.58% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS198158","Network Name":"AGNET-AS FIRMA USLUGOWO-HANDLOWA \"AG-net\" JOANNA MACZENSKA","Provider Family":"meganet.com.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"61.33","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #490 with 61.33% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS198364","Network Name":"BANATSYNC SRL","Provider Family":"banatsync.com","Country":"RO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Current abuse-concentration hosting review candidate","Abuse Band":"High","Abuse %":"12.76","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this hosting ASN #944 with 12.76% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling.","Source IDs":"S03, N01"},{"ASN":"AS198401","Network Name":"GECKONET-AS Geckonet Sp. z o. o.","Provider Family":"geckonet.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"32.16","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #573 with 32.16% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS198418","Network Name":"CELcom CELCOM SPOLKA Z OGRANICZONA ODPOWIEDZIALNOSCIA","Provider Family":"celcom.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"46.64","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #528 with 46.64% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS198525","Network Name":"CLIMAX-AS ClimaxNET sp. z o.o.","Provider Family":"climaxnet.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"99.22","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #463 with 99.22% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS198550","Network Name":"nodehost-as NODE HOST LIMITED","Provider Family":"NODE HOST LIMITED","Country":"GB","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Conditional fast-flux ASN seed","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Conditional fast-flux analytic includes this ASN. This supports source-scoped review, not provider-wide malicious attribution.","Recommended Use":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior.","Source IDs":"N38, N01"},{"ASN":"AS198793","Network Name":"Benda IP Benda Artyom Sergeevich","Provider Family":"","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"14.06","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #868 with 14.06% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS198910","Network Name":"NETPAK-AS NETPAK Sp. z o.o","Provider Family":"netpak.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.19","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #761 with 17.19% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS199099","Network Name":"ERLION ERLION BILISIM LIMITED SIRKETI","Provider Family":"erlion.tr","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"50","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #512 with 50% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS199929","Network Name":"emircanapak-hostvera Emircan Apak","Provider Family":"bogahost.com","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"19.3","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #701 with 19.3% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS200192","Network Name":"Super-Optik Super Optik Tech LLC","Provider Family":"superoptic.net","Country":"AZ","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"26.95","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #603 with 26.95% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS200203","Network Name":"DATABRIDGE GLOBAL DATA BRIDGE INTERNATIONAL LIMITED","Provider Family":"databridge.international","Country":"GB","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse government review candidate","Abuse Band":"Very High","Abuse %":"27.47","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this government ASN #598 with 27.47% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS200391","Network Name":"KREZ999AS KREZ 999 EOOD","Provider Family":"fasthost.ltd","Country":"BG","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"15.23","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #812 with 15.23% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS200404","Network Name":"JETNET Jetnet Telekom Int. Bil.Hiz. San and Tic. LTD","Provider Family":"jetnetinternet.com.tr","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"66.41","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #483 with 66.41% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS200582","Network Name":"ORG-LO31-RIPE LLC O-NET","Provider Family":"o-net.com.ua","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.09","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #920 with 13.09% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS200750","Network Name":"KLIKOM_NET Klikom.net Sp.z o.o.","Provider Family":"klikom.net","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"80.95","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #473 with 80.95% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS200814","Network Name":"GAZIKNET LIMNET , LLC","Provider Family":"limnet.com.ua","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"18.88","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #715 with 18.88% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS201030","Network Name":"hostgeb-asn HOSTGEB BILISIM TEKNOLOJILERI SANAYI VE TICARET LIMITED SIRKETI","Provider Family":"nurullah.tr","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"26.56","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #607 with 26.56% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS201132","Network Name":"MSCode Mateusz Sikorski trading as MSCode","Provider Family":"mscode.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"12.89","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #931 with 12.89% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS201151","Network Name":"intermax InterMAX Regional Networks LLC","Provider Family":"intermax.net.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"22.56","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #657 with 22.56% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS201219","Network Name":"VSD Mushegh Baghdasaryan","Provider Family":"vcd.am","Country":"AM","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"30.86","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #581 with 30.86% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS201667","Network Name":"ASMBP LLC","Provider Family":"ipxo.com","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Current abuse-concentration hosting review candidate","Abuse Band":"Very High","Abuse %":"47.75","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this hosting ASN #525 with 47.75% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling.","Source IDs":"S03, N01"},{"ASN":"AS201884","Network Name":"am-ispsupport ISP SUPPORT LLC","Provider Family":"ispsupport.am","Country":"AM","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"16.64","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #778 with 16.64% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS202375","Network Name":"DIGITALBOX Digital Albox SL","Provider Family":"","Country":"ES","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"18.1","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #734 with 18.1% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS203003","Network Name":"Magna Capax Finland Oy","Provider Family":"magnacapax.fi","Country":"FI","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Current abuse-concentration hosting review candidate","Abuse Band":"High","Abuse %":"17.91","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this hosting ASN #743 with 17.91% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling.","Source IDs":"S03, N01"},{"ASN":"AS203140","Network Name":"NETUS NETUS Renata Gieruszczak-Fikus","Provider Family":"netusinternet.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.97","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #924 with 12.97% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS203320","Network Name":"TURIEN-AS Turien en Co. Assuradeuren B.V.","Provider Family":"turien.nl","Country":"NL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse banking review candidate","Abuse Band":"High","Abuse %":"16.41","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this banking ASN #785 with 16.41% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS203565","Network Name":"VRLAN-NET PE Gumenova Olga","Provider Family":"vrlan.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.89","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #934 with 12.89% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS203667","Network Name":"zipnet ZIPnet sp. z o.o.","Provider Family":"zipnet.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #783 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS204144","Network Name":"COMFORT-AS Comfort XXI Century Ltd.","Provider Family":"komfort21vek.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"16.86","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #769 with 16.86% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS204208","Network Name":"Peravix Group LTD","Provider Family":"peravix.co.uk","Country":"GB","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Current abuse-concentration hosting review candidate","Abuse Band":"Very High","Abuse %":"50","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this hosting ASN #515 with 50% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling.","Source IDs":"S03, N01"},{"ASN":"AS204685","Network Name":"MGN PE KRYVENKO SERGIY ANDRIYOVYCH","Provider Family":"","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"25.39","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #620 with 25.39% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS205100","Network Name":"F3NETZE F3 Netze e.V.","Provider Family":"f3netze.de","Country":"DE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.89","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #936 with 12.89% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS205146","Network Name":"avanet-as Bartlomiej Michal Czyz trading as F.P.H.U AVANET","Provider Family":"avanet.net.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"64.32","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #485 with 64.32% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS205463","Network Name":"VDSGLOBAL Pembe Gul Isguzar Karagoz","Provider Family":"vdsmerkezi.com","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"55.41","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #499 with 55.41% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS205872","Network Name":"EXTRANET-AS EXTRANET 2010","Provider Family":"exstranet.bg","Country":"BG","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"19.27","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #703 with 19.27% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS205980","Network Name":"WD-Corp W&D CORP - FZCO","Provider Family":"","Country":"AE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"39.45","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #540 with 39.45% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS206069","Network Name":"Cornseed Limited","Provider Family":"ipxo.com","Country":"GB","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Current abuse-concentration hosting review candidate","Abuse Band":"High","Abuse %":"17.42","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this hosting ASN #754 with 17.42% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling.","Source IDs":"S03, N01"},{"ASN":"AS206092","Network Name":"SECFIREWALLAS F.N.S. HOLDINGS LIMITED","Provider Family":"fns-holdings.com","Country":"CY","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"20.6","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #680 with 20.6% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS206388","Network Name":"ertebatatazinkia Gostaresh Ertebat Azin Kia Company PJSC","Provider Family":"","Country":"IR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.85","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #938 with 12.85% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS206680","Network Name":"PG19-Rovenki Consumer Internet Cooperative PG-19","Provider Family":"pg19.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"25","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #623 with 25% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS206803","Network Name":"asterabit LLC Terabit","Provider Family":"terabitvu.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"16.21","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #794 with 16.21% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS206813","Network Name":"AS4830org 4830.org e. V.","Provider Family":"4830.org","Country":"DE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"26.66","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #606 with 26.66% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS207423","Network Name":"STEILSOUTH-AS STEIL-SOUTH LTD","Provider Family":"stl-u.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"49.09","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #522 with 49.09% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS207461","Network Name":"host-industry HOSTING INDUSTRY LIMITED","Provider Family":"HOSTING INDUSTRY LIMITED","Country":"GB","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Point-IOC provider context","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Current origin of repeated Settra MeshAgent C2 endpoint 193.5.65.114. This supports source-scoped review, not provider-wide malicious attribution.","Recommended Use":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior.","Source IDs":"N41, N01"},{"ASN":"AS207462","Network Name":"LuxeNetwork Al-Jeel Al-Sabei Internet Services Co., Ltd","Provider Family":"","Country":"IQ","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"25.98","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #612 with 25.98% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS207475","Network Name":"RLAN FOP Onuschak Oleg Volodimirovich","Provider Family":"astra.in.ua","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"13.02","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #921 with 13.02% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS207483","Network Name":"NETVIA Netvia Bilisim Yazilim Dan. Tic. Ltd. Sti.","Provider Family":"netvia.com.tr","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"72.48","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #477 with 72.48% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS207830","Network Name":"LIMNET LIMNET , LLC","Provider Family":"limnet.com.ua","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"22.66","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #655 with 22.66% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS208142","Network Name":"Rocket-Telecom-AS LLC Rocket Telecom","Provider Family":"rocketcom.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"34.71","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #558 with 34.71% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS208314","Network Name":"ACCESSTELECOM Access Telecom Ltd.","Provider Family":"access52.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"11.98","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #986 with 11.98% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS208323","Network Name":"APPLIEDPRIVACY-AS Foundation for Applied Privacy","Provider Family":"appliedprivacy.net","Country":"AT","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"38.28","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #544 with 38.28% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS208356","Network Name":"SmartCities-AS Smart Cities Limited Liability Partnership","Provider Family":"scity.pro","Country":"KZ","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"28.52","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #593 with 28.52% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS208752","Network Name":"BaykonurSvyazInform-AS \"BaykonurSvyazInform\" SUE","Provider Family":"baykonur.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"15.23","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #822 with 15.23% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS208803","Network Name":"ACN ACN LLC","Provider Family":"acn.group","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"18.41","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #725 with 18.41% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS208843","Network Name":"ALPHASTRIKE-RESEARCH Alpha Strike Labs GmbH","Provider Family":"alphastrike.io","Country":"DE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"62.5","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #486 with 62.5% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS209078","Network Name":"AT-AS AMUDARYO TONER LLC","Provider Family":"","Country":"UZ","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"28.91","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #590 with 28.91% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS209219","Network Name":"asdin LLC Daginfonet","Provider Family":"daginfonet.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.48","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #752 with 17.48% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS209262","Network Name":"GSLine GSLINE LLC","Provider Family":"","Country":"AM","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.45","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #857 with 14.45% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS209275","Network Name":"NetMax NETMAX TELEKOMUNIKASYON ILETISIM HIZMETLERI TICARET LIMITED SIRKETI","Provider Family":"netmax.com.tr","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"34.77","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #556 with 34.77% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS209334","Network Name":"MODAT-01 Modat B.V.","Provider Family":"modat.io","Country":"NL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"22.66","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #653 with 22.66% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS209353","Network Name":"LABEL Maurizio Giuseppe Fanari trading as LABEL SISTEMI TECNOLOGICI","Provider Family":"fastweb.it","Country":"IT","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"26.46","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #610 with 26.46% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS209378","Network Name":"INIOS-AS Inios Oy","Provider Family":"Inios Oy","Country":"FI","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Conditional fast-flux ASN seed","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Conditional fast-flux analytic includes this ASN. This supports source-scoped review, not provider-wide malicious attribution.","Recommended Use":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior.","Source IDs":"N38, N01"},{"ASN":"AS209937","Network Name":"ASKUBTELE Kub-Telecom Ltd.","Provider Family":"","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"27.34","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #601 with 27.34% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS210067","Network Name":"SKYLINE-AS Chayka Vladimir","Provider Family":"","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"12.89","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #935 with 12.89% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS210135","Network Name":"YUG-TELECOM-K-AS Yug-Telecom-K Ltd.","Provider Family":"omicron.online","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"18.79","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #717 with 18.79% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS210238","Network Name":"Dieffeitalia Dieffeitalia.it S.r.l.","Provider Family":"dieffeitalia.it","Country":"IT","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.14","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #763 with 17.14% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS210557","Network Name":"FalakNET Houeiss and AI-Othman Internet Services LLC","Provider Family":"falaknet.online","Country":"SY","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"35.55","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #555 with 35.55% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS210634","Network Name":"YSTRONTEK-NETWORKS Suzhou Yesong Information Technology Co., Ltd.","Provider Family":"yesongit.com","Country":"CN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"18.88","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #713 with 18.88% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS210743","Network Name":"BABBAR-AS BABBAR SAS","Provider Family":"babbar.tech","Country":"FR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"53.13","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #503 with 53.13% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS210949","Network Name":"SanalSantral SANAL SANTRAL TELEKOMUNIKASYON TICARET ANONIM SIRKETI","Provider Family":"sanalsantral.com.tr","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #867 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS211190","Network Name":"QUICKNET QUICKNET LLC","Provider Family":"","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"15.54","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #808 with 15.54% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS211212","Network Name":"GBD-AS GBD Software as a Service Private Limited Company","Provider Family":"gbd.hu","Country":"HU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"24.9","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #625 with 24.9% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS211250","Network Name":"TELECOMTRADE-UA-AS TELECOM TRADE LLC","Provider Family":"westele.com.ua","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"28.32","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #594 with 28.32% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS211298","Network Name":"DRIFTNET Driftnet Ltd","Provider Family":"driftnet.io","Country":"GB","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #130 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS211496","Network Name":"surnet-gete SURNET ILETISIM TEKNOLOJI TIC VE SAN LTD STI","Provider Family":"surnet.com.tr","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"51.04","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #507 with 51.04% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS211504","Network Name":"AN-TV STUDIO AN-TV SRL","Provider Family":"","Country":"MD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"12.5","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #957 with 12.5% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS211560","Network Name":"UGUR-OZTURK Datafex Bilisim Teknolojileri Ticaret Limited Sirketi","Provider Family":"datafex.com.tr","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"14.84","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #834 with 14.84% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS211590","Network Name":"BUCKLOG Bucklog SARL","Provider Family":"tutamail.com","Country":"FR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"50.78","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #509 with 50.78% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS211680","Network Name":"AS-BITSIGHT NSEC - Sistemas Informaticos, S.A.","Provider Family":"bitsight.com","Country":"PT","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"55.27","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #500 with 55.27% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS211851","Network Name":"WEB9 SECKIN CAN CELENK trading as Web9 Bilisim ve Yazilim Hizmetleri","Provider Family":"w9.com.tr","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the Very High band at rank #607 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS211947","Network Name":"KREMEN-IX PP Vizit-Service","Provider Family":"vizit-net.com","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"32.03","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #574 with 32.03% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS211995","Network Name":"a2z A2Z Technologies CJSC","Provider Family":"a2z.az","Country":"AZ","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.49","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #847 with 14.49% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS212193","Network Name":"vivanet VIVA INTERNET LIMITED SIRKETI","Provider Family":"vivanet.com.tr","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"99.61","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #458 with 99.61% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS212280","Network Name":"AS212280-Storm Storm for Information Technology, Internet Services, Communications, Electronic Solutions, Software, and Automation LLC","Provider Family":"stormnetwork.net","Country":"IQ","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.72","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #946 with 12.72% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS212285","Network Name":"Linyitnet Linyit Net Telekomunikasyon Hizmetleri Sanayi ve Ticaret Ltd. Sti.","Provider Family":"linyitnet.com.tr","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"26.56","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #608 with 26.56% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS212432","Network Name":"SOYUZNET-AS Zishko Alexandr","Provider Family":"soyuznet.com.ua","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.84","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #835 with 14.84% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS212463","Network Name":"NGroup FOP Polischyk O.V","Provider Family":"netgroup.ua","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"15.23","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #814 with 15.23% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS212617","Network Name":"ALDEN-AS Lynnyk Olexii","Provider Family":"","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"19.53","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #699 with 19.53% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS212623","Network Name":"NYSANET-AS NysaNet sp. z o.o.","Provider Family":"nysanet.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #170 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS212641","Network Name":"INCOM Incom Net Ltd","Provider Family":"","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"15.04","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #828 with 15.04% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS212695","Network Name":"LTS-AS Link Telecom Service Ltd","Provider Family":"lts.org.ua","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"21.09","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #675 with 21.09% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS212825","Network Name":"NIMNET-AS Novitni Informaciini Merezhi Ltd","Provider Family":"nim-net.com.ua","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #895 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS213252","Network Name":"CENUTA Cenuta Telekomunikasyon Anonim Sirketi","Provider Family":"cenuta.com","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"52.54","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #504 with 52.54% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS213404","Network Name":"YstronTek-Networks Suzhou Yesong Information Technology Co., Ltd.","Provider Family":"yesongit.com","Country":"CN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"43.55","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #533 with 43.55% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS213412","Network Name":"ONYPHE ONYPHE SAS","Provider Family":"onyphe.io","Country":"FR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #134 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS213461","Network Name":"NorthernLightsCloud Igor Andreevich Nemtsov","Provider Family":"comfortel.pro","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"19.92","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #692 with 19.92% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS213474","Network Name":"Reserved ASN with active origin observed (former HOMELINE-AS HomeLine Broadband LLC)","Provider Family":"whitelabel.sh","Country":"ZZ","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Former ASN-DROP; registration and routing anomaly","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Present in the 2026-09-15 ASN-DROP snapshot and absent from the 2026-09-29 snapshot; delisting does not establish benignness.","Recommended Use":"Disabled by default. Retain history and review current assignment, origin, and exact indicators before any enforcement.","Source IDs":"S01, S02, N01"},{"ASN":"AS213498","Network Name":"INFRONET-AS Infronet-Telecom LLC","Provider Family":"infronet.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.89","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #933 with 12.89% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS213511","Network Name":"VSVK VSVK Onderhoud B.V.","Provider Family":"VSVK","Country":"NL","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"Recorded Future found that AS213511 used the identity of an unrelated Dutch construction company and operated through the Railnet ecosystem; the legitimate VSVK business denied involvement. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as VSVK (vonie.net).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, X031, N01, S03"},{"ASN":"AS213694","Network Name":"INLAN-AS INLAN LLC","Provider Family":"","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #985 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS213884","Network Name":"FAST-FIBER Reynaldo Papahan trading as FAST-FIBER NETWORK AND DATA SOLUTION","Provider Family":"fast-fiber.com.ph","Country":"PH","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"22.66","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #656 with 22.66% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS213999","Network Name":"THE-CLIENTS WorkTitans B.V.","Provider Family":"THE.Hosting clients","Country":"NL","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Unannounced or low-visibility ASN retained for review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"N/A","Evidence Summary":"The 2026-09-15 Spamhaus ASN-DROP feed associates AS213999 with stark-industries.solutions. This is a current block-oriented source signal, but no independent provider-level campaign attribution was established in this review. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as THE-CLIENTS (stark-industries.solutions).","Recommended Use":"Disabled. Re-enable only after fresh routing, holder identity, and threat-evidence validation.","Source IDs":"S01, S02, N01, S03"},{"ASN":"AS214209","Network Name":"INTERNET-MAGNATE Internet Magnate (Pty) Ltd","Provider Family":"magnates.co.za","Country":"ZA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"13.48","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #897 with 13.48% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS214210","Network Name":"ELEMENT PE Pigin Alexander Lirovich","Provider Family":"","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #964 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS214218","Network Name":"MIRONOV PE Mironova Lyudmila Alexandrovna","Provider Family":"","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"35.55","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #554 with 35.55% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS214268","Network Name":"ORANGE ORANGE LLC","Provider Family":"leveltele.com","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.32","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #759 with 17.32% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS214309","Network Name":"AURORIX Aurorix Gaming Solutions Limited","Provider Family":"aurorix.net","Country":"GB","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"12.89","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #930 with 12.89% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS214365","Network Name":"HypefoxNet Hypefox AB","Provider Family":"hypefox.net","Country":"SE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"25.39","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #619 with 25.39% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS214481","Network Name":"wczapkowicz-as Wojciech Czapkowicz","Provider Family":"chunkserve.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #998 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS214803","Network Name":"BRNCHOST Baran Cirak","Provider Family":"brnchost.com","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"26.95","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #605 with 26.95% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS214961","Network Name":"STELLARGROUPSAS Stellar Group SAS","Provider Family":"abuse-manager.com","Country":"FR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"22.46","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #659 with 22.46% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS215115","Network Name":"Optics-Kuban-AS Kovalishin Alexey Sergeevich PE","Provider Family":"","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.65","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #841 with 14.65% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS215125","Network Name":"Cyberology-AS Church of Cyberology","Provider Family":"cyberology.nl","Country":"NL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #187 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS215208","Network Name":"PT-Citra-Celebas-Multimedia PT Citra Celebas Multimedia","Provider Family":"","Country":"ID","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Legacy hosting/VPS watchlist","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Excedo's 2025 BPH analysis concerned the former holder Dolphin 1337 Limited. The current RIPE object was created on 2026-04-20 for Indonesian ISP PT Citra Celebas Multimedia, and bgp.tools classifies it as an active eyeball network. The historical reputation must not be transferred to the new holder.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S05, X004, X005, N01"},{"ASN":"AS215253","Network Name":"FAMKO-MOJEMEDIA-AS FAMKO Paulina Zwiazek","Provider Family":"mojemedia.net.pl","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"12.89","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #937 with 12.89% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS215288","Network Name":"HOBI-ONE Michele Branchini","Provider Family":"as215288.net","Country":"IT","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"15.63","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #806 with 15.63% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS215416","Network Name":"MagNet VIGEN PETROSYAN trading as \"SAMVELI\"","Provider Family":"","Country":"AM","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"27.34","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #599 with 27.34% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS215439","Network Name":"PLAY2GO-NET PLAY2GO INTERNATIONAL LIMITED","Provider Family":"PLAY2GO INTERNATIONAL LIMITED","Country":"GB","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Conditional fast-flux ASN seed","Abuse Band":"","Abuse %":"","FP Risk":"High","Evidence Summary":"Conditional fast-flux analytic includes this ASN. This supports source-scoped review, not provider-wide malicious attribution.","Recommended Use":"Disabled by default. Use only with the source analytic or exact IOC plus identity, device, session, DNS, or post-exploitation behavior.","Source IDs":"N38, N01"},{"ASN":"AS215462","Network Name":"Reserved ASN, origin withdrawn 2026-10-02 (former BUGGZ-HOSTING Noel Nayasha Materke)","Provider Family":"sircrosar.net","Country":"ZZ","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Former ASN-DROP; registration and routing anomaly","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"Present in the 2026-09-15 ASN-DROP snapshot and absent from the 2026-09-29 snapshot; delisting does not establish benignness. Direct RDAP returns no record, and the origin last observed on 2026-10-02 has since been withdrawn.","Recommended Use":"Disabled by default. Retain history and review current assignment, origin, and exact indicators before any enforcement.","Source IDs":"S01, S02, N01, S03"},{"ASN":"AS215654","Network Name":"GenicheskOnline Genichesk Online LLC","Provider Family":"","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.67","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #889 with 13.67% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS215761","Network Name":"MFATIHASAN Muhammed Fatih ASAN","Provider Family":"hostingturkiye.com.tr","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"37.24","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #548 with 37.24% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS215778","Network Name":"ALPHASTRIKE-HK Alpha Strike Labs GmbH","Provider Family":"alphastrike.io","Country":"DE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"57.71","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #494 with 57.71% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS215813","Network Name":"SAS-ALTISCORE Association Athena-Heberg","Provider Family":"athena-heberg.fr","Country":"FR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"17.58","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #751 with 17.58% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS215851","Network Name":"JOINNET-AS JoinNet LLC","Provider Family":"joinnet.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.11","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #978 with 12.11% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS215910","Network Name":"EDMA-NET Edma Net SHPK","Provider Family":"","Country":"AL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"25.39","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #617 with 25.39% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS216020","Network Name":"JORDANCAPPELLE-AS Jordan Cappelle t/a OCTOHEBERG","Provider Family":"octoheberg.fr","Country":"FR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"19.92","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #693 with 19.92% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS216046","Network Name":"tele-co-tirana Tele.Co.Albania SHPK","Provider Family":"","Country":"AL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.06","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #865 with 14.06% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS216185","Network Name":"Biletik_Onlain Biletik-Onlain LTD","Provider Family":"yapk-service.ru","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"14.45","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #848 with 14.45% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS216192","Network Name":"HIPERONLINE hiperonline iletisim hizmetleri san. tic. ltd. sti.","Provider Family":"hiperonline.com.tr","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.38","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #755 with 17.38% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS216472","Network Name":"HS-SYR High Speed For Internet Services L.L.C","Provider Family":"highspeed-sy.com","Country":"SY","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"21.53","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #668 with 21.53% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS218831","Network Name":"NL-NET Noah Lingsminat","Provider Family":"nl-net.de","Country":"DE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"17.97","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #740 with 17.97% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS218850","Network Name":"SETURA-YAZILIM SETURA YAZILIM VE TICARET LIMITED SIRKETI","Provider Family":"setura.tr","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"99.61","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #460 with 99.61% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS218923","Network Name":"SERVIS-NODE-AS SERVIS NODE LLC","Provider Family":"","Country":"UA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"58.59","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #493 with 58.59% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS218984","Network Name":"AR-Solution REENA DEVI ANURAG SACHAN trading as AR SOLUTION","Provider Family":"serververs.com","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"21.09","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #674 with 21.09% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS219064","Network Name":"Akenai-Products-AS Akenai Products LTD","Provider Family":"akenai.team","Country":"GB","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #905 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS219181","Network Name":"POSIINDUSTRIAL PO SI INDUSTRIAL CO., LIMITED","Provider Family":"ipv4superhub.com","Country":"HK","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the Very High band at rank #584 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS219231","Network Name":"Oretra ORETRA INTERNET VE BILISIM HIZMETLERI LIMITED SIRKETI","Provider Family":"","Country":"TR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"95.31","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #468 with 95.31% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS219335","Network Name":"COREVANCE-AS COREVANCE LTD","Provider Family":"corevance.org","Country":"GB","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"11.91","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #990 with 11.91% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS219543","Network Name":"PA1792-AS German Kiselev","Provider Family":"","Country":"RU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #745 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS262880","Network Name":"AS262880 - RADAR WISP LTDA","Provider Family":"radarinternet.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"19.17","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #704 with 19.17% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS262909","Network Name":"AS262909 - JK TELECOMUNICACOES LTDA","Provider Family":"jknet.com.br","Country":"BR","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"50","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #517 with 50% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS262988","Network Name":"AS262988 - Pombonet Telecomunicacoes e Informatica","Provider Family":"pombonet.net.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"50.84","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #508 with 50.84% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS263284","Network Name":"AS263284 - MAXXIMO INFORMATICA E TELECOMUNICACAO LTDA","Provider Family":"meganet.net.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"99.8","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #457 with 99.8% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS263351","Network Name":"AS263351 - Micron Servicos de Tecnologia Ltda","Provider Family":"micron.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"34.18","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #559 with 34.18% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS263536","Network Name":"AS263536 - MICROSET MAQUINAS E SERVICOS LTDA","Provider Family":"microset.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"44.64","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #530 with 44.64% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS263641","Network Name":"AS263641 - TCF Telecomunicacoes Campo Florido Ltda","Provider Family":"tcftelecom.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"31.49","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #577 with 31.49% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS263947","Network Name":"AS263947 - VirtualSpace Telecom","Provider Family":"virtualspaceprovedor.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"23.36","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #647 with 23.36% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS263949","Network Name":"AS263949 - Mega Internet LTDA ME","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.45","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #854 with 14.45% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS263983","Network Name":"AS263983 - CIT INFORMATICA","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"18.85","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #716 with 18.85% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS264009","Network Name":"AS264009 - INFIX TELECOM LTDA","Provider Family":"tbonet.net.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"16.75","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #774 with 16.75% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS264014","Network Name":"AS264014 - Led Internet Eireli","Provider Family":"ledinternet.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #169 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS264051","Network Name":"AS264051 - PLAYMAIS FIBRA SCM LTDA","Provider Family":"playmaisfibra.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"46.97","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #527 with 46.97% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS264133","Network Name":"AS264133 - TX WEB TELECOM LTDA","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.97","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #737 with 17.97% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS264217","Network Name":"AS264217 - Sem Fone Telecomunicacoes Ltda","Provider Family":"semfone.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #168 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS264280","Network Name":"AS264280 - Eagle Redes de Telecomunicacoes Ltda","Provider Family":"eagleredes.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"99.9","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #453 with 99.9% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS264697","Network Name":"AS264697 - LEWTEL SRL","Provider Family":"lewtel.com.ar","Country":"AR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.54","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #894 with 13.54% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS265131","Network Name":"AS265131 - GP4 SERVICOS E TECNOLOGIA LTDA","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"66.67","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #481 with 66.67% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS265191","Network Name":"AS265191 - Sapucaia Comercio e informatica ltda - me","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"15.76","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #800 with 15.76% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS265201","Network Name":"AS265201 - MEGANET SERVICOS DE COMUNICACAO E MULTIMIDIA LTDA","Provider Family":"telecab.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"11.82","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #1000 with 11.82% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS265260","Network Name":"AS265260 - JOSE APARECIDO PEREIRA DA SILVA TELNET - ME","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"16.41","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #789 with 16.41% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS265282","Network Name":"AS265282 - DOMINA NET TELECOM","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #176 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS265410","Network Name":"Reserved ASN, origin withdrawn 2026-09-30 (former AS265410 - JL INFORMATICA E TELECOM LTDA - ME)","Provider Family":"","Country":"ZZ","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Registration and routing anomaly","Abuse Band":"Very High","Abuse %":"44.44","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #531 with 44.44% observed abuse concentration (Very High) on 2026-09-29. Current delegated RIR data marks the ASN reserved with no current holder or country, direct RDAP returns no record, and the origin last observed on 2026-09-30 has since been withdrawn. The former holder and country remain only as historical context.","Recommended Use":"Disabled by default. Retain history and review current assignment, origin, and exact indicators before any enforcement.","Source IDs":"S03, N01"},{"ASN":"AS265464","Network Name":"AS265464 - ESTACAONET TELECOM","Provider Family":"estacaonet.net.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"33.33","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #566 with 33.33% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS265574","Network Name":"AS265574 - IPTVTEL COMUNICACIONES S DE RL DE CV","Provider Family":"","Country":"MX","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"25.68","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #614 with 25.68% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS265579","Network Name":"AS265579 - TELECOMUNICACIONES OTOMIES","Provider Family":"","Country":"MX","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"51.76","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #506 with 51.76% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS265772","Network Name":"AS265772 - SOTO DANIEL MARIO (Internet Compus)","Provider Family":"compusinformatica.com.ar","Country":"AR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"19.73","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #697 with 19.73% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS265868","Network Name":"AS265868 - GETCOM SAS","Provider Family":"","Country":"AR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"18.75","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #721 with 18.75% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS265879","Network Name":"AS265879 - COOPERATIVA DE OBRAS Y SERVICIOS PUBLICOS DE CANALS LIMITADA","Provider Family":"canalsnet.com.ar","Country":"AR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"55.86","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #497 with 55.86% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS265914","Network Name":"AS265914 - TRIUNFO FIBRA","Provider Family":"triunfointernet.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.55","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #844 with 14.55% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS266270","Network Name":"AS266270 - WBR Telecom","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"25.59","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #615 with 25.59% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS266498","Network Name":"AS266498 - UNIVERSO FIBER COMUNICACAO MULTIMIDIA","Provider Family":"universofiber.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"99.8","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #456 with 99.8% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS266583","Network Name":"AS266583 - TELXE DO BRASIL TELECOMUNICACOES LTDA","Provider Family":"telxe.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #915 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS266631","Network Name":"AS266631 - Enoki & Ruiz Ltda - ME","Provider Family":"futuranet.net.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"50","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #513 with 50% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS266705","Network Name":"AS266705 - GABRIEL FRANCISCO ERBETTA Y MARIANO ANDRES CARRIZO RICHELET SOCIEDAD DE HECHO (TELNET SOLUCIONES)","Provider Family":"jumpnetcorp.com.ar","Country":"AR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.71","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #838 with 14.71% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS266742","Network Name":"AS266742 - SOLUCIONES DCN NETWORK C.A","Provider Family":"","Country":"VE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"27.34","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #600 with 27.34% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS266852","Network Name":"AS266852 - SOCIEDAD PIRQUE NET LIMITADA","Provider Family":"intercable.cl","Country":"CL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"15.7","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #801 with 15.7% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS266953","Network Name":"AS266953 - ITMINDS CONSULTORIA EM TECNOLOGIA DA INFORMACAO","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #104 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS267325","Network Name":"AS267325 - USBINF INFORMATICA LTDA - ME","Provider Family":"usbinternet.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"66.67","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #480 with 66.67% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS267677","Network Name":"AS267677 - COMERCIALIZADORA E IMPORTADORA PRESTOM CHILE LTDA","Provider Family":"prestomwill.cl","Country":"CL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"21.39","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #671 with 21.39% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS267690","Network Name":"AS267690 - ELDA SALERNO(FULLNET)","Provider Family":"","Country":"AR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"41.93","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #537 with 41.93% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS267889","Network Name":"AS267889 - PROVINSAT CAPITAL SA","Provider Family":"provinsat.com.ar","Country":"AR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"18.75","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #719 with 18.75% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS267952","Network Name":"AS267952 - HILINK TECNOLOGIA E COMUNICACAO LTDA","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.79","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #943 with 12.79% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS268106","Network Name":"AS268106 - Link Speed","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #98 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS268502","Network Name":"AS268502 - Sinal do Ceu Telecom Comercio e Servicos Ltda","Provider Family":"sinaldoceu.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #96 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS268538","Network Name":"AS268538 - Conecta Network Telecom LTDA","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #97 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS268757","Network Name":"AS268757 - BRITO & GONCALVES LTDA ME","Provider Family":"pantanaltelecom.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"33.33","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #563 with 33.33% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS268876","Network Name":"AS268876 - CE TECH INTERNET LTDA","Provider Family":"cetech.net.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #837 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS268983","Network Name":"AS268983 - NAXOS TELECOM","Provider Family":"naxosfibra.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"99.8","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #455 with 99.8% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS269160","Network Name":"AS269160 - Dblock Net","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"15.16","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #825 with 15.16% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS269182","Network Name":"AS269182 - PLUGAR TELECOM","Provider Family":"plugartelecom.net.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"60","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #492 with 60% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS269195","Network Name":"AS269195 - J. CALUX & CIA LTDA","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"14.39","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #859 with 14.39% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS269279","Network Name":"AS269279 - ARENA TELECOM COMERCIO DE EQUIPAMENTOS DE INFORMA","Provider Family":"arenaconnect.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"80.08","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #474 with 80.08% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS269357","Network Name":"AS269357 - DELTA TELECOM","Provider Family":"delta-telecom.net","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"19.86","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #694 with 19.86% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS269422","Network Name":"AS269422 - GKG NET TELECON LTDA","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"36.36","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #550 with 36.36% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS269427","Network Name":"AS269427 - ONSTARK SISTEMAS INTELIGENTES LTDA -EPP","Provider Family":"onstark.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #1000 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS269494","Network Name":"AS269494 - GPR NET COMUNICACOES EIRELI","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"15.14","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #827 with 15.14% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS269546","Network Name":"AS269546 - BITNET TELECOM","Provider Family":"bitnetinternet.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"33.33","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #564 with 33.33% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS269630","Network Name":"AS269630 - Jose Carlos Santana Junior-ME","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"12.7","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #948 with 12.7% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS269663","Network Name":"AS269663 - CONNECTLINK TECH","Provider Family":"connectlinksp.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"23.73","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #640 with 23.73% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS269771","Network Name":"AS269771 - PRINTER-NET-SERVICE, C.A.","Provider Family":"pns.com.ve","Country":"VE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"16.02","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #796 with 16.02% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS269901","Network Name":"AS269901 - MARAVECA TELECOMUNICACIONES C.A","Provider Family":"maraveca.com","Country":"VE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.45","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #852 with 14.45% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS269930","Network Name":"AS269930 - CAMPOS FARIAS GUILHERME","Provider Family":"alfa.net.py","Country":"PY","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.5","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #960 with 12.5% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS270062","Network Name":"AS270062 - FIBERNET TV SAS","Provider Family":"fibernettv.com.co","Country":"CO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.72","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #749 with 17.72% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS270075","Network Name":"AS270075 - SUPER REDES S.A.S","Provider Family":"superredes.co","Country":"CO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"24.27","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #632 with 24.27% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS270168","Network Name":"AS270168 - Alejandro Uballe Montoya","Provider Family":"","Country":"MX","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #966 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS270207","Network Name":"AS270207 - MULTICARRIER JE S. DE R.L. DE C.V.","Provider Family":"multicarrier.com.mx","Country":"MX","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"12.82","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #940 with 12.82% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS270226","Network Name":"AS270226 - UGI INTERNET & TV S.A. de C.V.","Provider Family":"ugi.mx","Country":"MX","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"18.36","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #727 with 18.36% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS270268","Network Name":"AS270268 - FiberPon telecom","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"55.76","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #498 with 55.76% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS270320","Network Name":"AS270320 - X NET","Provider Family":"xnetfibra.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"18.13","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #732 with 18.13% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS270368","Network Name":"AS270368 - T. R. TELECOMUNICACOES LTDA","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"28.03","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #596 with 28.03% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS270433","Network Name":"AS270433 - maicon narciso me","Provider Family":"midiatelecom.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"57.14","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #495 with 57.14% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS270581","Network Name":"AS270581 - JET NETWORK TELECOMUNICACAO LTDA","Provider Family":"jetnetwork.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"49.8","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #519 with 49.8% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS270837","Network Name":"AS270837 - Imartech Fibra","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"50","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #518 with 50% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS270923","Network Name":"AS270923 - FENIX BRASIL","Provider Family":"fnxtelecom.net.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"33.33","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #568 with 33.33% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS270955","Network Name":"AS270955 - LINK DIGITAL SOLUCOES EM INTERNET LTDA","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.06","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #870 with 14.06% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS271380","Network Name":"AS271380 - GLOBAL CONECTA TELECOM EIRELI","Provider Family":"globalconecta.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #179 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS271388","Network Name":"AS271388 - WEB Provedor","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #197 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS271410","Network Name":"AS271410 - Smart Servico de Internet Ltda","Provider Family":"provedorsmartsp.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"33.33","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #565 with 33.33% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS271412","Network Name":"AS271412 - FR Sousa Telecomunicacoes LTDA - ME","Provider Family":"multpontosfranca.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"39.92","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #539 with 39.92% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS271562","Network Name":"AS271562 - WT NET COMUNICACAO LTDA","Provider Family":"winetfsa.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"30.86","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #582 with 30.86% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS271843","Network Name":"AS271843 - LARA INGENIERIA EN TECNOLOGIA Y TELECOMUNICACIONES LIMITADA (SOLUCIONES INTERLAN)","Provider Family":"interlan.cl","Country":"CL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.84","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #744 with 17.84% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS272042","Network Name":"AS272042 - Garay Diego Sebastian","Provider Family":"infomain.com.ar","Country":"AR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"18.46","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #724 with 18.46% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS272073","Network Name":"AS272073 - SILKGLOBAL DOMINICANA SRL","Provider Family":"silkglobal.com","Country":"DO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"16.21","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #792 with 16.21% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS272090","Network Name":"AS272090 - ALDERETE RIVAS JORDAN TOMAS SEBASTIAN (COMUNICATE INTERNET)","Provider Family":"netplay.com.ar","Country":"AR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"21.88","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #662 with 21.88% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS272102","Network Name":"AS272102 - BESSER SOLUTIONS C.A.","Provider Family":"bessersolutions.com","Country":"VE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"23.93","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #635 with 23.93% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS272149","Network Name":"AS272149 - DLD SERVICIO SRL","Provider Family":"dldservicio.com","Country":"DO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"50.39","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #511 with 50.39% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS272405","Network Name":"AS272405 - Jair Lozano","Provider Family":"","Country":"MX","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"12.99","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #922 with 12.99% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS272575","Network Name":"AS272575 - DELTA R SEGURANCA E SERVICOS","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #978 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS272605","Network Name":"AS272605 - GRUPO ULTRA FIBRA","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.15","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #915 with 13.15% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS272741","Network Name":"AS272741 - ATLANTICA TELECOMUNICACOES LTDA","Provider Family":"atlanticatelecom.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.97","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #831 with 14.97% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS272791","Network Name":"AS272791 - Riann Martins de Oliveira - ME","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"14.06","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #863 with 14.06% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS272876","Network Name":"AS272876 - EDWIN RAYMUNDO HERNANDEZ PEC (IMPORTADORA Y EXPORTADORA INTERCEL)","Provider Family":"","Country":"GT","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #180 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS272954","Network Name":"AS272954 - VUELATECHNOLOGY S.A.S.","Provider Family":"","Country":"EC","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"50.59","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #510 with 50.59% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS272990","Network Name":"AS272990 - AYSATEC TELECOMUNICACIONES S.A.S.","Provider Family":"aysatecsas.com.co","Country":"CO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"24.61","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #627 with 24.61% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273034","Network Name":"AS273034 - COMPANIA DE TELECOMUNICACIONES LEON & RODAS LR-COMPTEL S.A.","Provider Family":"workcom.ec","Country":"EC","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"18.75","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #720 with 18.75% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273061","Network Name":"AS273061 - VOZ Y TELEVISION SOCIEDAD ANONIMA CERRADA","Provider Family":"vozytelevision.org","Country":"PE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"16.41","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #783 with 16.41% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273113","Network Name":"AS273113 - ONERED JWG532 SRL","Provider Family":"","Country":"DO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"49.22","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #520 with 49.22% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273123","Network Name":"AS273123 - CRAMCOMNET CIA.LTDA.","Provider Family":"flylifecuador.com","Country":"EC","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.7","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #950 with 12.7% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273134","Network Name":"AS273134 - HOLA TELECOMUNICACINES COLOMBIA S.A.S","Provider Family":"holainternet.com.co","Country":"CO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.72","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #945 with 12.72% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273142","Network Name":"AS273142 - SERVICIOS DE TELCOMUNICACIONES LATEVECOM CIA LTDA","Provider Family":"fiberpon.net","Country":"EC","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"30.47","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #584 with 30.47% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273187","Network Name":"AS273187 - FIESTA TELECOMUNICACIONES SAS","Provider Family":"ftc.net.co","Country":"CO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"16.41","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #784 with 16.41% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273195","Network Name":"AS273195 - INTERPLUSNET EC CIA. LTDA.","Provider Family":"interplus.net.ec","Country":"EC","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"20.31","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #687 with 20.31% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273250","Network Name":"AS273250 - SOLUCIONES DE TECNOLOGIA JAH SA DE CV","Provider Family":"jahwifi.mx","Country":"MX","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"11.83","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #998 with 11.83% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273262","Network Name":"AS273262 - OSWALDO ERIVAN VALTIERRA ORNELAS","Provider Family":"","Country":"MX","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"14.06","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #862 with 14.06% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273306","Network Name":"AS273306 - CABLE DIVERSION ELIGAMA","Provider Family":"","Country":"MX","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.96","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #875 with 13.96% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273339","Network Name":"AS273339 - Su@net Provedor Ltda","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.45","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #850 with 14.45% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273433","Network Name":"AS273433 - INOVAR TELECOM","Provider Family":"inovartelecomse.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the Very High band at rank #678 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273470","Network Name":"AS273470 - WORK TELECOM INTERNET LTDA","Provider Family":"worktelecombj.com.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #99 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273692","Network Name":"AS273692 - ULTRA INTERNET LTDA","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"15.23","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #815 with 15.23% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273709","Network Name":"AS273709 - MR Serv Internet e TV por Assinatura","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"23.83","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #637 with 23.83% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273909","Network Name":"AS273909 - GENIOS SOLUCIONES SRL","Provider Family":"geniosoluciones.pro","Country":"DO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"18.36","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #726 with 18.36% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273916","Network Name":"AS273916 - JUAN CARLOS FRANCO LOBO (INTERCOM HN)","Provider Family":"intercomhn.com","Country":"HN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #965 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS273922","Network Name":"AS273922 - CONNET S.R.L.","Provider Family":"connetsrl.com.ar","Country":"AR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"19.14","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #705 with 19.14% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274095","Network Name":"AS274095 - YNS PARTNERS EIRL","Provider Family":"ynspartners.com","Country":"DO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"13.67","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #892 with 13.67% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274104","Network Name":"AS274104 - KING WIFI K NETWORK EIRL","Provider Family":"kingwifiknetwork.com","Country":"DO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the Very High band at rank #653 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274118","Network Name":"AS274118 - T AND T NETWORKS SOLUTIONS, C.A.","Provider Family":"","Country":"VE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"20.31","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #686 with 20.31% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274129","Network Name":"AS274129 - ABITAVERAS WIRELESS, S.R.L.","Provider Family":"abitaveraswireless.com","Country":"DO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"18.75","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #723 with 18.75% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274152","Network Name":"AS274152 - SURFLINK SAS","Provider Family":"","Country":"CO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.28","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #904 with 13.28% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274155","Network Name":"AS274155 - DIGITAL DOT GROUP SAS","Provider Family":"","Country":"CO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"13.67","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #893 with 13.67% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274178","Network Name":"AS274178 - CORPORACION PV NETWORKS S.A.C.","Provider Family":"ten.pe","Country":"PE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.89","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #928 with 12.89% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274191","Network Name":"AS274191 - CUSATO VICENTE EZEQUIEL (TELERED VGG)","Provider Family":"","Country":"AR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"16.8","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #773 with 16.8% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274202","Network Name":"AS274202 - GRUPO MULTIMEDIA S&G, C.A","Provider Family":"conet.com.ve","Country":"VE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #700 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274206","Network Name":"AS274206 - NORTE VISION CA","Provider Family":"multitel-nortevision.com","Country":"VE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"38.67","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #543 with 38.67% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274212","Network Name":"AS274212 - TELECABLE SPA","Provider Family":"telecable.cl","Country":"CL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"17.97","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #739 with 17.97% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274227","Network Name":"AS274227 - MOSSO MAYRA ADELA (INTERZONA FORMOSA)","Provider Family":"interzonafsa.com","Country":"AR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"23.44","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #646 with 23.44% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274252","Network Name":"AS274252 - ORELTELECOM S.A.S.","Provider Family":"ajcomputacion.com","Country":"EC","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"28.91","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #589 with 28.91% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274326","Network Name":"AS274326 - INTERNET AVALO SUA SRL","Provider Family":"suareznetwork.com","Country":"DO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"19.14","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #707 with 19.14% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274406","Network Name":"AS274406 - JUAN CARLOS CRUZ MUNOZ","Provider Family":"","Country":"MX","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"15.63","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #802 with 15.63% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274471","Network Name":"AS274471 - Wifi net servicos de telecomunicacoes","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.28","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #903 with 13.28% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274714","Network Name":"AS274714 - Net-Agro Servicos de Comunicacao LTDA","Provider Family":"netagro.net.br","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.67","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #888 with 13.67% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274762","Network Name":"AS274762 - MOBILELINK PROVEDOR DE SERVICOS DE INTERNET LTDA","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"19.53","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #698 with 19.53% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274894","Network Name":"AS274894 - TV GAITAN TELECOMUNICACIONES SAS","Provider Family":"unicomnet.co","Country":"CO","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"12.89","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #929 with 12.89% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274898","Network Name":"AS274898 - PEREZ CRISTIAN LEANDRO","Provider Family":"cyberuno.com.ar","Country":"AR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"15.23","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #821 with 15.23% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS274921","Network Name":"AS274921 - ARMOA BLANCA NOELIA","Provider Family":"inetrenzo.com.ar","Country":"AR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"30.86","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #580 with 30.86% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS275640","Network Name":"AS275640 - Headers Consultoria","Provider Family":"","Country":"BR","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"23.24","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #648 with 23.24% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS327991","Network Name":"Megasurf Wireless Internet CC - Megasurf Wireless Internet CC","Provider Family":"","Country":"ZA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"Very High","Abuse %":"33.11","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #570 with 33.11% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS329130","Network Name":"TAQNYAT ALJEEL COMPANY FOR COMMUNICATION AND INFORMATION TECHNOLOGY LTD - TAQNYAT ALJEEL COMPANY FOR COMMUNICATION AND INFORMATION TECHNOLOGY LTD","Provider Family":"aljeel.ly","Country":"LY","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"This ASN appeared in the High band at rank #970 in the 2026-09-11 ipapi.is snapshot but is absent from the 2026-09-29 top 1,000. Absence is not evidence of zero abuse.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS329409","Network Name":"JIJI FIBER LTD - JIJI FIBER LTD","Provider Family":"","Country":"KE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"16.41","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #787 with 16.41% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS329437","Network Name":"VENNET SOLUTIONS LIMITED - VENNET SOLUTIONS LIMITED","Provider Family":"veenet.africa","Country":"KE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"14.69","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #839 with 14.69% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS329618","Network Name":"Mpaps Internet Solution Limited - Mpaps Internet Solution Limited","Provider Family":"mpaps.co.ke","Country":"KE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"16.5","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #782 with 16.5% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS394711","Network Name":"KORGRID - KorGrid, LLC","Provider Family":"KorGrid","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Historical LIMENET evidence; current-holder continuity unresolved","Abuse Band":"","Abuse %":"","FP Risk":"Critical","Evidence Summary":"Censys described historical LIMENET AS394711 as a known bulletproof-hosting monolith; Rapid7 and time-matched Cisco Talos data add historical abuse context. The current holder is KORGRID / KorGrid LLC. Continuity or reassignment is unresolved, so the BPH label is not carried to the current holder and the row remains disabled.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N19, N35, N37, N01"},{"ASN":"AS396126","Network Name":"TUCAN - TRANS UNION OF CANADA, INC.","Provider Family":"transunion.com","Country":"CA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"12.5","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #961 with 12.5% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS396507","Network Name":"EMERALD-ONION - Emerald Onion","Provider Family":"emeraldonion.org","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"21.58","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #665 with 21.58% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS396982","Network Name":"GOOGLE-CLOUD-PLATFORM - Google LLC","Provider Family":"Google Cloud","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Broad cloud/CDN control row","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.","Recommended Use":"Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.","Source IDs":"N01"},{"ASN":"AS398324","Network Name":"CENSYS-ARIN-01 - Censys, Inc.","Provider Family":"censys.com","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #112 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS398705","Network Name":"CENSYS-ARIN-02 - Censys, Inc.","Provider Family":"censys.com","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #175 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS398722","Network Name":"CENSYS-ARIN-03 - Censys, Inc.","Provider Family":"censys.com","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #196 with 100% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS399566","Network Name":"BIGCOMMERCE - Bigcommerce Inc.","Provider Family":"bigcommerce.com","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"High","Abuse %":"15.04","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #829 with 15.04% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS401401","Network Name":"UNREDACTED-NOISENET - Unredacted Inc","Provider Family":"unredacted.org","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"98.05","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #467 with 98.05% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS401560","Network Name":"ONECABLE - OneCable Network LLC","Provider Family":"onecablenetwork.com","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse isp review candidate","Abuse Band":"High","Abuse %":"13.52","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this isp ASN #896 with 13.52% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS401661","Network Name":"EMBNEX-AS - EMBNEX, LLC","Provider Family":"embnex.com","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"High-abuse business review candidate","Abuse Band":"Very High","Abuse %":"20.7","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this business ASN #677 with 20.7% observed abuse concentration (Very High) on 2026-09-29.","Recommended Use":"Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.","Source IDs":"S03, N01"},{"ASN":"AS402170","Network Name":"Valor Holdings LLC","Provider Family":"valornode.net","Country":"US","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Current abuse-concentration hosting review candidate","Abuse Band":"High","Abuse %":"12.5","FP Risk":"Very High","Evidence Summary":"ipapi.is ranks this hosting ASN #954 with 12.5% observed abuse concentration (High) on 2026-09-29.","Recommended Use":"Disabled by default. Review tenant dependencies and require an exact IOC, repeated identity evidence, or local telemetry before enabling.","Source IDs":"S03, N01"},{"ASN":"AS401109","Network Name":"ZHONGGUANCUN-CO - Zhongguancun LLC","Provider Family":"zhongguancun.asia","Country":"US","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Former ASN-DROP; non-originating lifecycle review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"Present in the 2026-10-02 ASN-DROP snapshot and absent from the 2026-10-07 snapshot; delisting does not establish benignness.","Recommended Use":"Disabled by default. Retain history and review current assignment, origin, and exact indicators before any enforcement.","Source IDs":"S01, S02, N01, S03"},{"ASN":"AS401110","Network Name":"AS-SOVYCLOUD - Sovy Cloud Services","Provider Family":"sovy.cloud","Country":"US","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Former ASN-DROP; non-originating lifecycle review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"Present in the 2026-10-02 ASN-DROP snapshot and absent from the 2026-10-07 snapshot; delisting does not establish benignness.","Recommended Use":"Disabled by default. Retain history and review current assignment, origin, and exact indicators before any enforcement.","Source IDs":"S01, S02, N01, S03"},{"ASN":"AS401116","Network Name":"NYBULA - Nybula LLC","Provider Family":"nybula.com","Country":"US","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Former ASN-DROP; non-originating lifecycle review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"Present in the 2026-10-02 ASN-DROP snapshot and absent from the 2026-10-07 snapshot; delisting does not establish benignness.","Recommended Use":"Disabled by default. Retain history and review current assignment, origin, and exact indicators before any enforcement.","Source IDs":"S01, S02, N01, S03"},{"ASN":"AS401120","Network Name":"CHEAPY-HOST - cheapy.host LLC","Provider Family":"cheapy.host","Country":"US","Route Status":"Not currently originating","Tier":"T4 Review","Reason Disabled":"Former ASN-DROP; non-originating lifecycle review","Abuse Band":"Very High","Abuse %":"100","FP Risk":"Very High","Evidence Summary":"Present in the 2026-10-02 ASN-DROP snapshot and absent from the 2026-10-07 snapshot; delisting does not establish benignness.","Recommended Use":"Disabled by default. Retain history and review current assignment, origin, and exact indicators before any enforcement.","Source IDs":"S01, S02, N01, S03"},{"ASN":"AS8100","Network Name":"SPLICE-AS-AP - Splice Internet Pty Ltd","Provider Family":"SPLICE-AS-AP","Country":"AU","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS8100 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N06, N01"},{"ASN":"AS14315","Network Name":"1GSERVERS - 1GSERVERS, LLC","Provider Family":"1GSERVERS","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS14315 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N06, N01"},{"ASN":"AS21249","Network Name":"RUTIL-BG-AS Rutil Ltd.","Provider Family":"RUTIL-BG-AS Rutil Ltd.","Country":"BG","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS21249 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N06, N01"},{"ASN":"AS23470","Network Name":"RELIABLESITE - ReliableSite.Net LLC","Provider Family":"RELIABLESITE","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 3 time-bounded indicators attributed to or currently mapped to AS23470 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N06, N01"},{"ASN":"AS30633","Network Name":"LEASEWEB-USA-WDC - Leaseweb USA, Inc.","Provider Family":"LEASEWEB-USA-WDC","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS30633 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N06, N01"},{"ASN":"AS32613","Network Name":"IWEB-AS - Leaseweb Canada Inc.","Provider Family":"IWEB-AS","Country":"CA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS32613 across Akira and Fog ransomware via SonicWall SSL VPN. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N07, N01"},{"ASN":"AS36352","Network Name":"AS-COLOCROSSING - HostPapa","Provider Family":"AS-COLOCROSSING","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS36352 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N06, N01"},{"ASN":"AS43641","Network Name":"Sollutium-NL SOLLUTIUM EU Sp z.o.o.","Provider Family":"Sollutium-NL SOLLUTIUM EU Sp z.o.o.","Country":"PL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS43641 across Akira and Fog ransomware via SonicWall SSL VPN. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N07, N01"},{"ASN":"AS55286","Network Name":"SERVER-MANIA - B2 Net Solutions Inc.","Provider Family":"ServerMania / B2 Net Solutions","Country":"CA","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Eight Proofpoint cloud login-source IOCs historically originated from AS55286 during the campaign window. Use as a step-up signal because ServerMania is shared hosting.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"S04, S06, N01"},{"ASN":"AS60602","Network Name":"INOVARE-AS Inovare-Prim SRL","Provider Family":"INOVARE-AS Inovare-Prim SRL","Country":"MD","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS60602 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N06, N01"},{"ASN":"AS62005","Network Name":"BV-EU-AS BlueVPS OU","Provider Family":"BlueVPS","Country":"EE","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 5 time-bounded indicators attributed to or currently mapped to AS62005 across Akira ransomware targeting SonicWall SSL VPN; MuddyWater / BugSleep infrastructure cluster. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N06, N08, N01"},{"ASN":"AS62904","Network Name":"AS62904 - Eonix Corporation","Provider Family":"AS62904","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS62904 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N06, N01"},{"ASN":"AS63473","Network Name":"HOSTHATCH - HostHatch, LLC","Provider Family":"HOSTHATCH","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS63473 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N06, N01"},{"ASN":"AS64236","Network Name":"UNREAL-SERVERS - UnReal Servers, LLC","Provider Family":"UNREAL-SERVERS","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS64236 across Akira and Fog ransomware via SonicWall SSL VPN; Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N07, N06, N01"},{"ASN":"AS131199","Network Name":"NEXEON-AS-AP - Nexeon Technologies, Inc.","Provider Family":"NEXEON-AS-AP","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS131199 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N06, N01"},{"ASN":"AS215703","Network Name":"FREAKHOSTING FREAKHOSTING LTD","Provider Family":"FREAKHOSTING FREAKHOSTING LTD","Country":"GB","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS215703 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N06, N01"},{"ASN":"AS396356","Network Name":"LATITUDE-SH - Latitude.sh","Provider Family":"LATITUDE-SH","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS396356 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N06, N01"},{"ASN":"AS50867","Network Name":"ORG-LVA15-AS HOSTKEY B.V.","Provider Family":"ORG-LVA15-AS HOSTKEY B.V.","Country":"NL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS50867 across Console Chaos FortiGate management-interface exploitation. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N09, N01"},{"ASN":"AS149440","Network Name":"EVOXTSDNBHD-AS-AP - Evoxt Sdn. Bhd.","Provider Family":"EVOXTSDNBHD-AS-AP","Country":"MY","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS149440 across Console Chaos FortiGate management-interface exploitation. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N09, N01"},{"ASN":"AS399629","Network Name":"BLNWX - BL Networks","Provider Family":"BLNWX","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS399629 across Console Chaos FortiGate management-interface exploitation. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N09, N01"},{"ASN":"AS203020","Network Name":"HostRoyale HostRoyale Technologies Pvt Ltd","Provider Family":"HostRoyale","Country":"IN","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS203020 across MuddyWater / BugSleep infrastructure cluster. This does not implicate the provider or every tenant.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N08, N01"},{"ASN":"AS43350","Network Name":"NFORCE NForce Entertainment B.V.","Provider Family":"NForce","Country":"NL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"GreyNoise attributed most of over 9 million GlobalProtect login sessions, late September to mid-October 2025, to four ASNs including AS43350.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N60, N01"},{"ASN":"AS215929","Network Name":"datacampus Data Campus Limited","Provider Family":"Data Campus","Country":"HK","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"GreyNoise attributed most of over 9 million GlobalProtect login sessions, late September to mid-October 2025, to four ASNs including AS215929.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N60, N01"},{"ASN":"AS211632","Network Name":"ORG-ISI14-RIPE Internet Solutions & Innovations LTD.","Provider Family":"Internet Solutions & Innovations","Country":"SC","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"GreyNoise attributed most of over 9 million GlobalProtect login sessions, late September to mid-October 2025, to four ASNs including AS211632.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N60, N01"},{"ASN":"AS214238","Network Name":"iwihost HOST TELECOM LTD","Provider Family":"HOST TELECOM","Country":"GB","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"eSentire saw post-takedown Tycoon 2FA Microsoft 365 login attempts from AS214238, and ProxyLine use through it in Gmail-targeted campaigns since at least February 2026.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N10, N01"},{"ASN":"AS204957","Network Name":"GREENFLOID-AS ROUTE 95 LLC","Provider Family":"GREEN FLOID","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"eSentire saw post-takedown Tycoon 2FA Microsoft 365 login attempts from AS204957.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N10, N01"},{"ASN":"AS35758","Network Name":"HQSERV_NETWORKS Rachamim Aviel Twito","Provider Family":"HQSERV","Country":"IL","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Check Point reported Microsoft 365 password spray waves on 2026-03-03, 03-13 and 03-23 against Israel and the UAE using commercial VPN nodes hosted at AS35758, including Windscribe exits geolocated in Israel.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N61, N01"},{"ASN":"AS400940","Network Name":"RAILWAY - Railway","Provider Family":"Railway","Country":"US","Route Status":"Announced","Tier":"T4 Review","Reason Disabled":"Campaign watch ended; retained for history","Abuse Band":"","Abuse %":"","FP Risk":"Very High","Evidence Summary":"Huntress tied a device-code phishing and token replay campaign against 344 organizations, 2026-02-19 to mid-March 2026, to Railway PaaS ranges 162.220.232.0/22 and 162.220.234.0/22, with 162.220.234.41 the dominant token engine. Microsoft listed both ranges as threat actor infrastructure observed with sign-in on 2026-04-06.","Recommended Use":"Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.","Source IDs":"N58, N59, N01"}],"sources":[{"Source ID":"S01","Publisher":"Spamhaus","Title":"ASN-DROP","Published / Updated":"2026-10-09","URL":"https://www.spamhaus.org/drop/asndrop.json","Source Type":"Current machine-readable feed","Supports":"Current membership in Spamhaus ASN-DROP; coarse network-risk signal for rogue routing/transit infrastructure.","Limitations":"Membership and allocations can change. Neither list membership nor removal establishes every address/customer intent or login-source attribution. Update regularly before enforcement."},{"Source ID":"S02","Publisher":"CISA, NSA, FBI and international partners","Title":"Bulletproof Defense: Mitigating Risks From Bulletproof Hosting Providers","Published / Updated":"2025-11-19","URL":"https://media.defense.gov/2025/Nov/19/2003826020/-1/-1/0/CSI_BULLETPROOF_DEFENSE_MITIGATING_RISKS_FROM_BULLETPROOF_HOSTING_PROVIDERS.PDF","Source Type":"Joint government guidance","Supports":"Tiering, baselining, allowlisting, logging ASN plus IP, regular refresh and careful choice of ASN/range/IP granularity.","Limitations":"Warns that whole-ASN blocking can affect legitimate users and that BPH providers cycle infrastructure."},{"Source ID":"S03","Publisher":"ipapi.is","Title":"Most Abusive ASNs","Published / Updated":"2026-09-29","URL":"https://ipapi.is/most-abusive-asn.html","Source Type":"Current abuse-concentration ranking","Supports":"Current top 1,000 ASNs ranked by observed abuse concentration and organization type; refreshed by exact ASN match.","Limitations":"Vendor methodology and labels are prioritization signals, not malicious-login probability. Absence from the top 1,000 is not zero abuse; tied 100% ranks make rank-only movement weak evidence."},{"Source ID":"S04","Publisher":"Proofpoint","Title":"Cloud Credential Compromise from Russian Infrastructure","Published / Updated":"2022-03-03","URL":"https://www.proofpoint.com/us/blog/cloud-security/cloud-credential-compromise-campaign-originating-russian-affiliated","Source Type":"Cloud credential attack report with 35 IP IOCs","Supports":"Historical sign-in attack infrastructure. RIPE RIS enrichment maps 25 IOCs to AS62240, eight to AS55286 and two to AS16276 during the campaign window.","Limitations":"Proofpoint published IPs, provider labels and domains, not ASNs or CIDRs. ASN mapping is historical analyst enrichment and does not imply provider complicity."},{"Source ID":"S05","Publisher":"RIPE NCC","Title":"RIPEstat AS Overview","Published / Updated":"2026-09-15","URL":"https://stat.ripe.net/docs/data-api/api-endpoints/as-overview/","Source Type":"Registry/routing enrichment","Supports":"Current ASN holder and announcement state used for reconciliation.","Limitations":"Registry identity and routing status can change; country is not actor nationality."},{"Source ID":"S06","Publisher":"RIPE NCC","Title":"RIPEstat Routing History","Published / Updated":"2026-09-15","URL":"https://stat.ripe.net/docs/data-api/api-endpoints/routing-history/","Source Type":"Historical BGP enrichment method","Supports":"Historical ASN and prefix mapping for published IP indicators.","Limitations":"BGP origin establishes routing at a point in time, not ownership, intent or provider complicity."},{"Source ID":"S07","Publisher":"Microsoft","Title":"ACTINIUM targets Ukrainian organizations","Published / Updated":"2022-02-04","URL":"https://www.microsoft.com/en-us/security/blog/2022/02/04/actinium-targets-ukrainian-organizations/","Source Type":"Threat research","Supports":"More than 70% of 200-plus observed ACTINIUM operational IPs were in AS197695.","Limitations":"Actor infrastructure and C2 evidence, not Microsoft 365 login-source evidence. Microsoft describes REG.RU as legitimate."},{"Source ID":"S08","Publisher":"Palo Alto Networks Unit 42","Title":"Gamaredon (Primitive Bear) Russian APT Group Actively Targeting Ukraine","Published / Updated":"2022-02-03","URL":"https://unit42.paloaltonetworks.com/gamaredon-primitive-bear-ukraine-update-2021/","Source Type":"Threat research with IP/ASN mappings","Supports":"Historical AS197695 concentration and exact Gamaredon C2/downloader IPs, plus short-lived IPs in other ASNs.","Limitations":"Mostly malware C2/downloader telemetry, not authentication-source evidence. Large shared providers create ASN-wide false positives."},{"Source ID":"S09","Publisher":"U.S. Department of the Treasury","Title":"Treasury Sanctions Global Bulletproof Hosting Service Enabling Cybercriminals and Technology Theft","Published / Updated":"2025-07-01","URL":"https://home.treasury.gov/news/press-releases/sb0185","Source Type":"Official designation","Supports":"Aeza Group designation as a bulletproof hosting provider supporting cybercriminal activity.","Limitations":"The press release names the entity but not ASNs; ASN linkage comes from technical research and current registry data."},{"Source ID":"S10","Publisher":"U.S. Department of the Treasury","Title":"United States, Australia, and the United Kingdom Jointly Sanction Key Infrastructure that Enables Ransomware Attacks","Published / Updated":"2025-02-11","URL":"https://home.treasury.gov/news/press-releases/sb0018","Source Type":"Official designation","Supports":"Zservers designation for providing bulletproof hosting to LockBit and other cybercriminals.","Limitations":"The release names the entity, not a complete current ASN inventory."},{"Source ID":"S11","Publisher":"U.S. Department of Justice","Title":"Three Russian Nationals and Two Companies Indicted for International Cybercrimes Resulting in More Than $62M in Victim Losses","Published / Updated":"2026-07-14","URL":"https://www.justice.gov/opa/pr/three-russian-nationals-and-two-companies-indicted-international-cybercrimes-resulting-more","Source Type":"Official indictment announcement","Supports":"Media Land and ML Cloud bulletproof-hosting allegations and operational context.","Limitations":"Criminal charges are allegations until proven. The release is not a complete ASN or prefix feed."},{"Source ID":"S12","Publisher":"Recorded Future Insikt Group","Title":"One Step Ahead: Stark Industries Solutions Preempts EU Sanctions","Published / Updated":"2025-08-27","URL":"https://www.recordedfuture.com/research/one-step-ahead-stark-industries-solutions-preempts-eu-sanctions","Source Type":"Infrastructure research","Supports":"AS44477 transition, AS209847 creation, migration to AS33993 and 21 reported AS33993 prefixes.","Limitations":"Infrastructure was already shifting; revalidate current routing and ownership before enforcement."},{"Source ID":"S13","Publisher":"GreyNoise","Title":"The Stark Industries Shell Game","Published / Updated":"2025-11-17","URL":"https://www.greynoise.io/blog/stark-industries-shell-game","Source Type":"Infrastructure and scanning research","Supports":"Observed transition from AS44477 to AS209847 and malicious scanning context.","Limitations":"Observed scanning does not make every customer or sign-in malicious."},{"Source ID":"S14","Publisher":"Silent Push","Title":"IOFA Detects Aeza Group Infrastructure Shift Following OFAC Sanctions","Published / Updated":"2025-07-24","URL":"https://www.silentpush.com/news/iofa-detects-aeza-group-infrastructure/","Source Type":"Infrastructure research","Supports":"Technical ASN linkage for Aeza Group and related infrastructure changes.","Limitations":"Use the source date and routing snapshot; provider infrastructure can move."},{"Source ID":"S15","Publisher":"Intel 471","Title":"Zservers: Bulletproof Hosting for Crime","Published / Updated":"2025-03-11","URL":"https://www.intel471.com/blog/zservers-bulletproof-hosting-for-crime","Source Type":"Infrastructure research","Supports":"Maps Zservers/XHOST activity to AS197414 and two reported /24 ranges.","Limitations":"Historical technical snapshot. AS197414 is currently unannounced in this workbook enrichment."},{"Source ID":"S16","Publisher":"Team Cymru","Title":"Exploring Seychelles: Team Cymru’s Tech Adventure","Published / Updated":"2022-09-10","URL":"https://www.team-cymru.com/post/exploring-seychelles","Source Type":"Infrastructure research","Supports":"Links ELITETEAM/1337TEAM to AS39770, AS60424, AS56873 and AS51381.","Limitations":"Historical family mapping; current routing and current feed membership are shown separately."},{"Source ID":"S18","Publisher":"Microsoft","Title":"Midnight Blizzard: Guidance for responders on nation-state attack","Published / Updated":"2024-01-25","URL":"https://www.microsoft.com/en-us/security/blog/2024/01/25/midnight-blizzard-guidance-for-responders-on-nation-state-attack/","Source Type":"Identity-attack guidance","Supports":"Explains residential proxy rotation and why fixed IP/ASN IOCs are incomplete for Russian identity attacks.","Limitations":"Publishes no ASN list."},{"Source ID":"S19","Publisher":"Google Cloud Mandiant","Title":"APT29 Continues Targeting Microsoft 365","Published / Updated":"2022-08-18","URL":"https://cloud.google.com/blog/topics/threat-intelligence/apt29-continues-targeting-microsoft","Source Type":"Identity-attack research","Supports":"Shows use of residential proxies and Azure VMs in external subscriptions for M365 attacks.","Limitations":"Publishes no ASN list; behavior supports combining network and identity signals."},{"Source ID":"S20","Publisher":"Team Cymru","Title":"Operationalizing OFAC Sanctions for Financial Defense: MediaLand AS206728","Published / Updated":"2026-02-04","URL":"https://www.team-cymru.com/post/ofac-sanctions-compliance-active-risk-medialand-as206728","Source Type":"Current infrastructure research","Supports":"Maps Media Land to AS206728 and documents continuing operational risk.","Limitations":"Treat current routes and exact resources as time-sensitive."},{"Source ID":"X001","Publisher":"Rapid7","Title":"Ongoing Social Engineering Campaign Refreshes Payloads","Published / Updated":"2024-08-12","URL":"https://www.rapid7.com/blog/post/2024/08/12/ongoing-social-engineering-campaign-refreshes-payloads/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS48282.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X002","Publisher":"Silent Push","Title":"USPS Phishing on a Bulletproof Hosting Network","Published / Updated":"2024-08-12","URL":"https://www.silentpush.com/blog/usps-phishing-on-a-bulletproof-hosting-network/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS48282.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X003","Publisher":"Recorded Future","Title":"Malicious Infrastructure Finds Stability with aurologic GmbH","Published / Updated":"2025-11-06","URL":"https://assets.recordedfuture.com/insikt-report-pdfs/2025/cta-2025-1106.pdf","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS30823.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X004","Publisher":"Excedo","Title":"How cybercriminals abuse ASN for bulletproof hosting","Published / Updated":"2026-09-15","URL":"https://www.excedo.se/en/blog-articles/how-cybercriminals-are-abusing-autonomous-system-numbers-asn-for-bulletproof-hosting","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS214497.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X005","Publisher":"bgp.tools","Title":"bgp.tools AS215208 current registration","Published / Updated":"2025-05-01","URL":"https://bgp.tools/as/215208","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS215208.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X006","Publisher":"bgp.tools","Title":"bgp.tools AS215240 current registration","Published / Updated":"2025-05-01","URL":"https://bgp.tools/as/215240","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS215240.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X007","Publisher":"Team Cymru","Title":"How Virtual Offices Enable a Facade of Legitimacy","Published / Updated":"2025-05-01","URL":"https://www.team-cymru.com/post/how-virtual-offices-enable-a-facade-of-legitimacy","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS215240.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X008","Publisher":"Huntress","Title":"No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack","Published / Updated":"2026-07-15","URL":"https://www.huntress.com/blog/lshiy-password-spray-attack","Source Type":"Primary identity threat research with exact infrastructure","Supports":"Entra ID password and token spray from 2a0a:d683::/32 on LSHIY AS32167, 2026-06-12 to 06-26; LSHIY suspended the BYOIP customer on 07-02; operators then moved to FranTech AS53667 and 3xK AS200373.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X009","Publisher":"bgp.tools","Title":"bgp.tools AS207569","Published / Updated":"","URL":"https://bgp.tools/as/207569","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS207569.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X010","Publisher":"urlhaus.abuse.ch","Title":"URLhaus malware URL database","Published / Updated":"","URL":"https://urlhaus.abuse.ch/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS207569.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X011","Publisher":"global.ptsecurity.com","Title":"Lazarus Group Recruitment: Threat Hunters vs Head Hunters","Published / Updated":"2024-08-19","URL":"https://global.ptsecurity.com/en/research/pt-esc-threat-intelligence/lazarus-recruitment/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS26496.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X012","Publisher":"urlhaus.abuse.ch","Title":"URLhaus ASN report for AS26496","Published / Updated":"2024-08-19","URL":"https://urlhaus.abuse.ch/hoster/AS26496/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS26496.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X013","Publisher":"bgp.he.net","Title":"Hurricane Electric BGP Toolkit AS214943","Published / Updated":"2025-10-27","URL":"https://bgp.he.net/AS214943","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS214943.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X014","Publisher":"rdap.arin.net","Title":"ARIN RDAP lookup (no current object)","Published / Updated":"","URL":"https://rdap.arin.net/registry/autnum/11331","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS11331.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X015","Publisher":"bgp.tools","Title":"bgp.tools AS11938","Published / Updated":"","URL":"https://bgp.tools/as/11938","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS11938.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X016","Publisher":"halcyon.ai","Title":"Update: Cloudzy Command and Control Provider Report","Published / Updated":"2026-07-24","URL":"https://www.halcyon.ai/blog/update-cloudzy-command-and-control-provider-report","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS14956.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X017","Publisher":"cloudzy.com","Title":"Cloudzy Official Statement, August 2023","Published / Updated":"2026-07-24","URL":"https://cloudzy.com/news/official-statement-august-2023/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS14956.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X018","Publisher":"jumpsec.com","Title":"Inside a DPRK BlueNoroff ClickFix Kit","Published / Updated":"2026-07-24","URL":"https://www.jumpsec.com/inside-a-dprk-bluenoroff-clickfix-kit/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS14956.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X019","Publisher":"bgp.tools","Title":"bgp.tools AS22295","Published / Updated":"","URL":"https://bgp.tools/as/22295","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS22295.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X020","Publisher":"threatfox.abuse.ch","Title":"ThreatFox ASN report for AS22295","Published / Updated":"","URL":"https://threatfox.abuse.ch/asn/22295/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS22295.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X021","Publisher":"rdap.arin.net","Title":"ARIN RDAP lookup (no current object)","Published / Updated":"","URL":"https://rdap.arin.net/registry/autnum/22801","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS22801.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X022","Publisher":"bgp.tools","Title":"bgp.tools AS26701","Published / Updated":"","URL":"https://bgp.tools/as/26701","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS26701.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X023","Publisher":"rdap.arin.net","Title":"ARIN RDAP lookup (no current object)","Published / Updated":"","URL":"https://rdap.arin.net/registry/autnum/27524","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS27524.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X024","Publisher":"rdap.arin.net","Title":"ARIN RDAP lookup (no current object)","Published / Updated":"","URL":"https://rdap.arin.net/registry/autnum/32177","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS32177.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X025","Publisher":"rdap.arin.net","Title":"ARIN RDAP lookup (no current object)","Published / Updated":"","URL":"https://rdap.arin.net/registry/autnum/32558","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS32558.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X026","Publisher":"bgp.tools","Title":"bgp.tools AS42624 successor context","Published / Updated":"2025-11-06","URL":"https://bgp.tools/as/42624","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS34888.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X027","Publisher":"bgp.tools","Title":"bgp.tools AS35346","Published / Updated":"","URL":"https://bgp.tools/as/35346","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS35346.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X028","Publisher":"bgp.tools","Title":"bgp.tools AS35718","Published / Updated":"","URL":"https://bgp.tools/as/35718","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS35718.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X029","Publisher":"bgplookingglass.com","Title":"List of Autonomous System Numbers - 2 (historical identity reference)","Published / Updated":"2026-09-15","URL":"https://www.bgplookingglass.com/list-of-autonomous-system-numbers-2","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS40403.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X030","Publisher":"ipinfo.io","Title":"IPinfo AS41947 historical ASN summary","Published / Updated":"2026-09-15","URL":"https://ipinfo.io/AS41947","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS41947.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X031","Publisher":"Recorded Future","Title":"Malicious Infrastructure Finds Stability with aurologic GmbH","Published / Updated":"2026-04-23","URL":"https://www.recordedfuture.com/research/malicious-infrastructure-finds-stability-with-aurologic-gmbh","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS42624.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X032","Publisher":"bgp.he.net","Title":"Hurricane Electric BGP Toolkit: AS42624","Published / Updated":"2026-04-23","URL":"https://bgp.he.net/AS42624","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS42624.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X033","Publisher":"ipinfo.io","Title":"IPinfo AS43094 ASN summary","Published / Updated":"2026-09-15","URL":"https://ipinfo.io/AS43094","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS43094.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X034","Publisher":"x.com","Title":"Spamhaus researcher report on suspicious AS44317/AS21738 announcements","Published / Updated":"2024-05-16","URL":"https://x.com/spamhaus/status/1791118679645593845","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS44317.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X035","Publisher":"peeringdb.com","Title":"PeeringDB historical entry: AS44317 Mercury Telecom LLC","Published / Updated":"2024-05-16","URL":"https://www.peeringdb.com/asn/44317","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS44317.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X036","Publisher":"krebsonsecurity.com","Title":"Stark Industries Solutions: An Iron Hammer in the Cloud","Published / Updated":"2026-05-29","URL":"https://krebsonsecurity.com/2024/05/stark-industries-solutions-an-iron-hammer-in-the-cloud/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS44477.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X037","Publisher":"augursecurity.com","Title":"European Union Sanctions Force Stark Industries Solutions Ltd. to Rebrand Again","Published / Updated":"2026-05-29","URL":"https://www.augursecurity.com/post/european-union-sanctions-force-stark-industries-solutions-ltd-to-rebrand-again","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS44477.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X038","Publisher":"bgp.he.net","Title":"Hurricane Electric BGP Toolkit: AS44477","Published / Updated":"2026-05-29","URL":"https://bgp.he.net/AS44477","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS44477.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X039","Publisher":"bgp.tools","Title":"BGP.Tools: AS44589","Published / Updated":"2026-09-15","URL":"https://bgp.tools/as/44589","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS44589.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X040","Publisher":"ipinfo.io","Title":"IPinfo AS44774 historical ASN summary","Published / Updated":"2025-05-20","URL":"https://ipinfo.io/AS44774","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS44774.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X041","Publisher":"Silent Push","Title":"Infrastructure Laundering: Silent Push Exposes Cloudy Behavior Around FUNNULL CDN Renting IPs from Big Tech","Published / Updated":"2026-03-25","URL":"https://www.silentpush.com/blog/infrastructure-laundering/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS45753.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X042","Publisher":"greynoise.io","Title":"Ghost Fleet: Half of All New Scanning IPs Last Week Geolocated to Hong Kong","Published / Updated":"2026-03-25","URL":"https://www.greynoise.io/blog/ghost-fleet-half-new-scanning-ips-geolocated-to-hong-kong","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS45753.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X043","Publisher":"peeringdb.com","Title":"PeeringDB: AS45753","Published / Updated":"2026-03-25","URL":"https://www.peeringdb.com/asn/45753","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS45753.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X044","Publisher":"ipinfo.io","Title":"IPinfo AS47500 ASN summary","Published / Updated":"2026-09-15","URL":"https://ipinfo.io/AS47500","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS47500.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X045","Publisher":"Team Cymru","Title":"Team Cymru: Jingle Shells - How Virtual Offices Enable a Facade of Legitimacy","Published / Updated":"2026-09-15","URL":"https://www.team-cymru.com/post/jingle-shells-how-virtual-offices-enable-a-facade-of-legitimacy","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS48090.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X046","Publisher":"threatfox.abuse.ch","Title":"ThreatFox AS49042 tag","Published / Updated":"2026-09-15","URL":"https://threatfox.abuse.ch/browse/tag/AS49042/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS49042.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X047","Publisher":"urlhaus.abuse.ch","Title":"URLhaus ASN report for AS49042","Published / Updated":"2026-09-15","URL":"https://urlhaus.abuse.ch/asn/49042/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS49042.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X048","Publisher":"bgp.tools","Title":"BGP.Tools historical profile for AS49042","Published / Updated":"2026-09-15","URL":"https://bgp.tools/as/49042","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS49042.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X049","Publisher":"threatfox.abuse.ch","Title":"ThreatFox AS49217 tag","Published / Updated":"2026-09-15","URL":"https://threatfox.abuse.ch/browse/tag/AS49217/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS49217.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X050","Publisher":"bgp.tools","Title":"BGP.Tools historical profile for AS49217","Published / Updated":"2026-09-15","URL":"https://bgp.tools/as/49217","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS49217.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X051","Publisher":"alfa-inet.net","Title":"Alfa-inet ISP website","Published / Updated":"2026-09-15","URL":"https://alfa-inet.net/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS50138.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X052","Publisher":"rasvtv.md","Title":"RASV-TV official website","Published / Updated":"2026-09-15","URL":"https://rasvtv.md/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS51246.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X053","Publisher":"pfcloud.io","Title":"Pfcloud official service catalog","Published / Updated":"2026-09-15","URL":"https://pfcloud.io/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS51396.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X054","Publisher":"urlhaus.abuse.ch","Title":"URLhaus ASN report for AS51396","Published / Updated":"2026-09-15","URL":"https://urlhaus.abuse.ch/asn/51396/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS51396.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X055","Publisher":"rootlayer.net","Title":"RootLayer network and hosting page","Published / Updated":"2026-09-15","URL":"https://rootlayer.net/network/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS51447.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X056","Publisher":"ip2location.com","Title":"IP2Location current AS51490 status","Published / Updated":"2026-09-15","URL":"https://www.ip2location.com/as51490","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS51490.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X057","Publisher":"Recorded Future","Title":"Recorded Future 2022 Adversary Infrastructure Report","Published / Updated":"2026-09-15","URL":"https://www.recordedfuture.com/research/2022-adversary-infrastructure-report","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS57523.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X058","Publisher":"bgp.tools","Title":"BGP.Tools profile for AS57678","Published / Updated":"2026-09-15","URL":"https://bgp.tools/as/57678","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS57678.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X059","Publisher":"innetra.com","Title":"INNETRA official service catalog","Published / Updated":"2026-09-15","URL":"https://innetra.com/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS58349.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X060","Publisher":"peeringdb.com","Title":"PeeringDB AS58349 profile","Published / Updated":"2026-09-15","URL":"https://www.peeringdb.com/asn/58349","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS58349.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X061","Publisher":"xserver.cloud","Title":"XServer official VPS and dedicated-server site","Published / Updated":"2026-09-15","URL":"https://xserver.cloud/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS48031.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X062","Publisher":"bgp.tools","Title":"BGP.Tools AS48031 profile","Published / Updated":"2026-09-15","URL":"https://bgp.tools/as/48031","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS48031.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X063","Publisher":"docs.hetzner.com","Title":"Hetzner official documentation","Published / Updated":"2026-09-15","URL":"https://docs.hetzner.com/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS213230.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X064","Publisher":"peeringdb.com","Title":"PeeringDB AS213230 profile","Published / Updated":"2026-09-15","URL":"https://www.peeringdb.com/asn/213230","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS213230.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X065","Publisher":"learn.microsoft.com","Title":"Microsoft Learn: Internet peering and AS8075","Published / Updated":"2026-09-15","URL":"https://learn.microsoft.com/en-us/azure/internet-peering/internet-peering-vs-peering-service","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS8075.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X066","Publisher":"azure.microsoft.com","Title":"Microsoft Azure official site","Published / Updated":"2026-09-15","URL":"https://azure.microsoft.com/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS8075.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X067","Publisher":"serveroffer.lt","Title":"Serveroffer official hosting page","Published / Updated":"2026-09-15","URL":"https://serveroffer.lt/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS209605.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X068","Publisher":"m247.com","Title":"M247 official service catalog","Published / Updated":"2026-09-15","URL":"https://m247.com/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS9009.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X069","Publisher":"urlhaus.abuse.ch","Title":"URLhaus ASN report for AS9009","Published / Updated":"2026-09-15","URL":"https://urlhaus.abuse.ch/asn/9009/","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS9009.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X070","Publisher":"Recorded Future","Title":"GrayBravo's CastleLoader Activity Clusters Target Multiple Industries","Published / Updated":"2025-12-09","URL":"https://www.recordedfuture.com/research/graybravos-castleloader-activity-clusters-target-multiple-industries","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS211659.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X071","Publisher":"infosec.exchange","Title":"Spamhaus: 49.3 Networking bulletproof-host investigation","Published / Updated":"2025-09-26","URL":"https://infosec.exchange/@spamhaus/115270763024502133","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS399979.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X072","Publisher":"infosec.exchange","Title":"Spamhaus: Bearhost's bulletproof-hosting comeback","Published / Updated":"2026-04-29","URL":"https://infosec.exchange/@spamhaus/116488118532640901","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS201738.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X073","Publisher":"infosec.exchange","Title":"Spamhaus: Netiface bulletproof-hosting infrastructure","Published / Updated":"2026-08-24","URL":"https://infosec.exchange/@spamhaus/117150614554456244","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS36680.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X074","Publisher":"infosec.exchange","Title":"Spamhaus: AS219067 phishing and prefix-hopping infrastructure","Published / Updated":"2026-08-24","URL":"https://infosec.exchange/@spamhaus/117150614533611970","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS219067.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X075","Publisher":"infosec.exchange","Title":"Spamhaus: Virtualine bulletproof hosting","Published / Updated":"2025-09-18","URL":"https://infosec.exchange/@spamhaus/115225449245944633","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS202412.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"X076","Publisher":"infosec.exchange","Title":"Spamhaus: infrastructure facilitating bulletproof-host proliferation","Published / Updated":"2026-08-24","URL":"https://infosec.exchange/@spamhaus/117150614543659573","Source Type":"Supporting research or registry record","Supports":"Evidence, identity or context for AS51396.","Limitations":"Review the source scope and date. Inclusion does not imply every customer or the provider is malicious."},{"Source ID":"N01","Publisher":"RIPE NCC","Title":"RIPEstat AS Overview, RIR registration, and routing status","Published / Updated":"2026-10-07","URL":"https://stat.ripe.net/docs/data-api/","Source Type":"Current routing and registration metadata","Supports":"Current holder, RIR registration country/status, and origin visibility from all five RIR snapshots and RIPEstat.","Limitations":"RIR country is holder-registration metadata, not user or IP geolocation. A non-originating result can be transit-only, dormant, or below the RIPE visibility threshold; opaque RIR IDs are not stable ownership identifiers."},{"Source ID":"N02","Publisher":"stamparm","Title":"IPsum threat-intelligence feed","Published / Updated":"2026-09-29","URL":"https://github.com/stamparm/ipsum","Source Type":"Community IP reputation aggregation","Supports":"Current exact-IP enrichment: 121,838 IPv4 values; 17,604 score at least 3 and 4,242 score at least 5.","Limitations":"Underlying lists are not statistically independent. Score and ASN concentration are context, not automatic provider-tier evidence."},{"Source ID":"N03","Publisher":"mzyui","Title":"HTTP proxy list","Published / Updated":"2026-08-29","URL":"https://github.com/mzyui/proxy-list","Source Type":"Community open-proxy list","Supports":"Potential HTTP proxy endpoints for discovery only.","Limitations":"Artifact remained byte-identical and about 31.8 days stale after 143 consecutive updater failures when checked 2026-09-29; two invalid endpoint rows are excluded."},{"Source ID":"N04","Publisher":"duggytuxy","Title":"Data-Shield IPv4 Blocklist","Published / Updated":"2026-09-29","URL":"https://github.com/duggytuxy/Data-Shield_IPv4_Blocklist","Source Type":"Community IPv4 blocklist","Supports":"Current exact-IP enrichment from 92,896 IPv4 values.","Limitations":"Large overlap with IPsum prevents treating cross-list presence as independent corroboration. Use exact-IP context and short review TTLs."},{"Source ID":"N05","Publisher":"CAIDA","Title":"RouteViews Prefix-to-AS dataset","Published / Updated":"2026-09-13","URL":"https://www.caida.org/catalog/datasets/routeviews-prefix2as/","Source Type":"Routing dataset","Supports":"Current and historical prefix-to-origin-AS mapping.","Limitations":"Origin-AS mappings change over time and MOAS routes require separate handling."},{"Source ID":"N06","Publisher":"Arctic Wolf","Title":"July 2025 Uptick in Akira Ransomware Activity Targeting SonicWall SSL VPN","Published / Updated":"2025-08-04","URL":"https://arcticwolf.com/resources/blog/arctic-wolf-observes-july-2025-uptick-in-akira-ransomware-activity-targeting-sonicwall-ssl-vpn/","Source Type":"Vendor incident research with IOCs","Supports":"SonicWall VPN source infrastructure and Akira intrusion context.","Limitations":"The listed hosting networks are not inherently malicious; Arctic Wolf recommends limiting any blocking to VPN authentication."},{"Source ID":"N07","Publisher":"Arctic Wolf","Title":"Fog and Akira Ransomware Operations Linked to SonicWall SSL VPN","Published / Updated":"2024-10-24","URL":"https://arcticwolf.com/resources/blog/fog-and-akira-ransomware-operations-linked-to-sonicwall-ssl-vpn/","Source Type":"Vendor incident research with IOCs","Supports":"VPN initial access, rapid lateral movement, exfiltration, and ransomware infrastructure.","Limitations":"Historical exact-IP evidence; routing and ownership must be revalidated."},{"Source ID":"N08","Publisher":"Augur Security","Title":"Iran 2026 Threat Posture Assessment","Published / Updated":"2026","URL":"https://www.augursecurity.com/post/threat-research-iran-2026-threat-posture-assessment","Source Type":"Threat assessment with network ranges","Supports":"MuddyWater / BugSleep provider diversification and CIDRs including AS62005, AS62240, and AS203020.","Limitations":"Campaign infrastructure does not imply provider complicity or actor nationality for every event."},{"Source ID":"N09","Publisher":"Arctic Wolf","Title":"Console Chaos: A Campaign Targeting Publicly Exposed Management Interfaces on Fortinet FortiGate Firewalls","Published / Updated":"2025-01-10","URL":"https://arcticwolf.com/resources/blog/console-chaos-targets-fortinet-fortigate-firewalls/","Source Type":"Vendor incident research with IOCs","Supports":"FortiGate management-interface exploitation, account changes, VPN changes, and DCSync.","Limitations":"Exact IPs are time-bounded; broad VPS and CDN networks require behavioral corroboration."},{"Source ID":"N10","Publisher":"eSentire","Title":"Tycoon 2FA Infrastructure Update","Published / Updated":"2026-04-01","URL":"https://www.esentire.com/blog/tycoon-2fa-infrastructure-update-threat-actors-adapt-following-global-coalition-takedown","Source Type":"Identity threat research","Supports":"Tycoon 2FA Microsoft 365 login attempts from AS215540, AS9009 and AS29802 before the March 2026 takedown and AS214238, AS62240, AS204957, AS395092 and AS9009 after it; ProxyLine via AS214238.","Limitations":"Infrastructure use does not establish provider complicity."},{"Source ID":"N11","Publisher":"Okta","Title":"Human-operated phishing kit targets cryptocurrency firms","Published / Updated":"2026","URL":"https://www.okta.com/blog/threat-intelligence/human-operated-phishing-kit-targets-cryptocurrency-firms/","Source Type":"Identity threat research","Supports":"Credential theft and authentication attempts through AS62240 / ProxyLine.","Limitations":"Shared hosting and proxy infrastructure can have legitimate customers."},{"Source ID":"N12","Publisher":"Huntress","Title":"Exploitation of SonicWall VPN","Published / Updated":"2025","URL":"https://www.huntress.com/blog/exploitation-of-sonicwall-vpn","Source Type":"Vendor incident research","Supports":"SonicWall exploitation and source-infrastructure context.","Limitations":"Use with vulnerability, authentication, and post-access telemetry."},{"Source ID":"N13","Publisher":"The DFIR Report","Title":"Navigating Through the Fog","Published / Updated":"2025-04-28","URL":"https://thedfirreport.com/2025/04/28/navigating-through-the-fog/","Source Type":"Intrusion report","Supports":"Fog ransomware and Sliver infrastructure involving AS62240.","Limitations":"Incident-specific infrastructure does not imply all provider space is malicious."},{"Source ID":"N14","Publisher":"Recorded Future","Title":"Exposing TAG-53 Credential-Harvesting Infrastructure for Russia-Aligned Espionage Operations","Published / Updated":"2024","URL":"https://www.recordedfuture.com/research/exposing-tag-53-credential-harvesting-infrastructure-for-russia-aligned-espionage-operations","Source Type":"Threat-actor infrastructure report","Supports":"Credential-harvesting infrastructure involving AS62240.","Limitations":"Attribution applies to campaign infrastructure, not provider ownership."},{"Source ID":"N15","Publisher":"Coralogix / Snowbit","Title":"Evil Token: AI-Enabled Device Code Phishing Campaign","Published / Updated":"2026","URL":"https://coralogix.com/blog/evil-token-ai-enabled-device-code-phishing-campaign/","Source Type":"Identity threat research with IOC","Supports":"Device-code phishing and token replay from PacketHub AS136787.","Limitations":"Exact IP and campaign context are time-bounded."},{"Source ID":"N16","Publisher":"Resecurity","Title":"SharePoint Zero-Day Exploit CVE-2025-53770 Network Infrastructure Mapping","Published / Updated":"2025","URL":"https://www.resecurity.com/blog/article/sharepoint-zero-day-exploit-cve-2025-53770-network-infrastructure-mapping","Source Type":"Exploitation infrastructure report","Supports":"ToolShell infrastructure in PacketHub-assigned AS62240 space.","Limitations":"IP allocation and current origin can change; no provider complicity is asserted."},{"Source ID":"N17","Publisher":"Google Threat Intelligence Group","Title":"UNC6671 Targets Financial Services and Enterprise Cloud Environments","Published / Updated":"2026-08-06","URL":"https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments","Source Type":"Primary threat-intelligence report with IOCs","Supports":"Vishing, AiTM, commercial VPN, phishing backend, and SaaS exfiltration infrastructure.","Limitations":"Most source IPs were commercial VPN nodes and cycle quickly; residential ASNs should not be blocklisted."},{"Source ID":"N18","Publisher":"Push Security","Title":"We infiltrated a criminal phishing panel: here is what we found","Published / Updated":"2026-05-07","URL":"https://pushsecurity.com/blog/inside-criminal-phishing-panel","Source Type":"Primary phishing-panel research with hashes","Supports":"Doko panel clusters hosted on MEVSPACE and Njalla.","Limitations":"Short-lived domains and operator-gated pages reduce static IOC durability."},{"Source ID":"N19","Publisher":"Censys","Title":"Hiding in Plain Sight: Tracking Bulletproof Hosting and Abused RDP Infrastructure","Published / Updated":"2026-02-03","URL":"https://censys.com/blog/hiding-in-plain-sight-tracking-bulletproof-hosting-and-abused-rdp-infrastructure/","Source Type":"Internet-measurement threat research","Supports":"BPH methodology and evidence for FlokiNET, historical LIMENET, and FIRST SERVER infrastructure.","Limitations":"Censys distinguishes legitimate VPS abuse from BPH and warns attribution can be uncertain."},{"Source ID":"N20","Publisher":"Cisco Talos","Title":"ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365","Published / Updated":"2026-07-01","URL":"https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/","Source Type":"Primary identity-threat research with IOCs","Supports":"Device-code phishing, PRT persistence, BEC, and SharePoint exfiltration.","Limitations":"Cloudflare-hosted indicators do not support adding or blocking the whole Cloudflare ASN."},{"Source ID":"N21","Publisher":"Team Cymru","Title":"Validating ShinyHunters Cyber Threat Actors Infrastructure","Published / Updated":"2026-08-05","URL":"https://www.team-cymru.com/post/validating-shinyhunters-cyber-threat-actors-infrastructure","Source Type":"Threat-infrastructure research","Supports":"Corroborates MEVSPACE and Njalla phishing-panel infrastructure.","Limitations":"Campaign infrastructure is narrower than provider-wide attribution."},{"Source ID":"N22","Publisher":"Sophos","Title":"Malicious Use of Virtual Machine Infrastructure","Published / Updated":"2026-02-04","URL":"https://www.sophos.com/en-us/blog/malicious-use-of-virtual-machine-infrastructure","Source Type":"Threat research","Supports":"Suspicious reused VM, C2, and brute-force-as-a-service artifacts involving FIRST SERVER networks.","Limitations":"Shared VM infrastructure can create provider-level false positives."},{"Source ID":"N23","Publisher":"Arctic Wolf","Title":"Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms","Published / Updated":"2026-09-03","URL":"https://arcticwolf.com/resources/blog/security-bulletin-active-cloud-data-theft-and-extortion-campaign-targeting-microsoft-365-and-saas-platforms/","Source Type":"Vendor security bulletin","Supports":"PREY-0058 identity compromise, app IDs, recon, and exfiltration patterns.","Limitations":"Detection thresholds require tenant baselining."},{"Source ID":"N24","Publisher":"Google Threat Intelligence Group","Title":"Disrupting the Largest Residential Proxy Network","Published / Updated":"2026-01-28","URL":"https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network","Source Type":"Primary disruption report","Supports":"IPIDEA residential-proxy abuse and disruption.","Limitations":"Residential proxy use makes actor geography and ASN-wide treatment unreliable."},{"Source ID":"N25","Publisher":"Google Threat Intelligence Group","Title":"Google Continues Disruption of Residential Proxy Networks","Published / Updated":"2026-07-02","URL":"https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks","Source Type":"Primary disruption report","Supports":"NetNut residential-proxy abuse and disruption.","Limitations":"Residential access ASNs must not be treated as malicious wholesale."},{"Source ID":"N26","Publisher":"Google Threat Intelligence Group","Title":"Expansion of ShinyHunters SaaS Data Theft","Published / Updated":"2026-01-30","URL":"https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft","Source Type":"Primary threat-intelligence report","Supports":"Identity-led SaaS data theft and extortion TTPs.","Limitations":"TTP correlation is more durable than infrastructure-only matching."},{"Source ID":"N27","Publisher":"Microsoft Security","Title":"Passkey-Themed Social Engineering Leads to Identity and Cloud Compromise","Published / Updated":"2026-09-09","URL":"https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/","Source Type":"Primary identity-threat research with domains","Supports":"Passkey-themed phishing, rogue enrollment, and cloud compromise.","Limitations":"Domain indicators rotate; monitor authentication and enrollment behavior."},{"Source ID":"N28","Publisher":"FBI","Title":"AVrecon Malware-Infected Routers Exploited as Residential Proxies by SocksEscort","Published / Updated":"2026-03","URL":"https://www.fbi.gov/file-repository/cyber-alerts/avrecon-malware-infected-routers-exploited-as-residential-proxies-by-socksescort.pdf","Source Type":"Government cyber alert","Supports":"Compromised routers used as residential proxies.","Limitations":"The subscriber ASN and country can be innocent infrastructure."},{"Source ID":"N29","Publisher":"PacketHub","Title":"PacketHub official service site","Published / Updated":"2026-09-15","URL":"https://www.packethub.net/","Source Type":"Official provider information","Supports":"Global hosting, colocation, connectivity, server footprint, and legal identity.","Limitations":"Provider marketing does not independently establish threat activity."},{"Source ID":"N30","Publisher":"Netify","Title":"NordVPN network and infrastructure profile","Published / Updated":"2026-09-15","URL":"https://www.netify.ai/resources/vpns/nordvpn","Source Type":"Network intelligence profile","Supports":"Operational association between NordVPN traffic and PacketHub infrastructure.","Limitations":"Association is not evidence of corporate ownership or malicious operation."},{"Source ID":"N31","Publisher":"Qurium","Title":"Weaponizing Proxy and VPN Providers","Published / Updated":"2026-09-15","URL":"https://www.qurium.org/weaponizing-proxy-and-vpn-providers/vpn-providers/","Source Type":"Civil-society network research","Supports":"VPN-provider infrastructure relationships and abuse context.","Limitations":"Network relationships can change and do not imply all users are malicious."},{"Source ID":"N32","Publisher":"Microsoft Security","Title":"AI-Enabled Device Code Phishing Campaign","Published / Updated":"2026-04-06","URL":"https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/","Source Type":"Primary identity-threat research","Supports":"Device-code phishing campaign underlying EvilTokens reporting.","Limitations":"Focus on OAuth device-code and token behavior, not infrastructure alone."},{"Source ID":"N33","Publisher":"Ransomware.live","Title":"Ransomware.live IoCs","Published / Updated":"2026-09-29","URL":"https://www.ransomware.live/ioc","Source Type":"Dynamic multi-group IOC repository","Supports":"Dynamic ransomware IOC discovery: 2,564 records across 216 groups.","Limitations":"The IP counter mixes bare IPv4, IPv4:port, and CIDR rows; public rows lack reliable observation dates and original source references. Revalidate exact indicators and do not promote an ASN from presence alone."},{"Source ID":"N34","Publisher":"Elastic Security Labs","Title":"Detecting Tycoon 2FA AiTM Attacks Across Entra ID and Google Workspace","Published / Updated":"2026-05-26","URL":"https://www.elastic.co/security-labs/threat-command/tycoon-2fa-aitm-detection-engineering","Source Type":"Detection engineering and threat research","Supports":"Cross-ASN session behavior, device persistence, Graph recon, and Tycoon infrastructure.","Limitations":"Cloud IP geolocation is unreliable for infrastructure classification; ASN is context, not verdict."},{"Source ID":"N35","Publisher":"Cisco Talos","Title":"Large-Scale Brute-Force Activity Targeting VPNs and SSH Services","Published / Updated":"2024-04-16","URL":"https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/","Source Type":"Primary threat advisory with IOC repository","Supports":"Anonymizer and proxy-sourced brute force against VPN, web authentication, and SSH.","Limitations":"Source IPs change. Campaign-time RouteViews mapping must be kept separate from current IP-to-AS mapping."},{"Source ID":"N36","Publisher":"StrongVPN","Title":"StrongVPN official service site","Published / Updated":"2026-09-15","URL":"https://strongvpn.org/","Source Type":"Official provider information","Supports":"Commercial VPN service and provider-family context.","Limitations":"Official provider information does not establish malicious activity or complicity."},{"Source ID":"N37","Publisher":"Rapid7","Title":"Ongoing Malvertising Campaign Leads to Ransomware","Published / Updated":"2024-05-13","URL":"https://www.rapid7.com/blog/post/2024/05/13/ongoing-malvertising-campaign-leads-to-ransomware/","Source Type":"Vendor incident research","Supports":"Historical LIMENET AS394711 infrastructure in a ransomware malvertising chain.","Limitations":"Historical holder continuity to current KORGRID is unresolved."},{"Source ID":"N38","Publisher":"Silent Push","Title":"Silent Push Tracks a Mass Phishing Operation Through Fast Flux","Published / Updated":"2026-09-15","URL":"https://www.silentpush.com/blog/fast-flux-phishing/","Source Type":"Primary vendor investigation","Supports":"Seven explicitly named ASNs form a conditional DNS-diversity analytic; Canada-first banking and callback phishing, Keitaro cloaking, live credential/OTP interception, fast-flux service delegation. Media Land/Yalishanda and ShadowRelay are discussed.","Limitations":"Publication explicitly warns not every ASN in the rotation is bulletproof. ASN set is an analytic seed, not a blanket deny list. DNSPod and Keitaro are legitimate shared services."},{"Source ID":"N39","Publisher":"GreyNoise","Title":"Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation","Published / Updated":"2026-09-21","URL":"https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation","Source Type":"Primary vendor investigation","Supports":"Three public IPs for staging, C2, and exploitation; wildcard C2 domain and three backdoor hashes. Activity spans May-September 2026 and multiple edge/web vulnerabilities.","Limitations":"Main persistent exploitation IP remains redacted; do not infer or de-redact it. Red Heron relationship and Chinese-speaking attribution are assessed, not proven. Published addresses do not imply provider complicity."},{"Source ID":"N40","Publisher":"GreyNoise","Title":"Swarming Against Citrix 0-Day Exploitation","Published / Updated":"2026-09-28","URL":"https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation","Source Type":"Primary vendor telemetry","Supports":"149.104.78.141 attempted CVE-2026-88771 exploitation on September 24; webshell path/hash and alias artifacts published.","Limitations":"Attempt against the Swarm sensor did not establish a foothold. IOC set is incomplete. Exact IP evidence is strong; same origin ASN alone is not proof of related attack activity."},{"Source ID":"N41","Publisher":"Huntress","Title":"Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM","Published / Updated":"2026-09-17","URL":"https://www.huntress.com/blog/new-settra-ransomware-variant","Source Type":"Primary vendor incident research","Supports":"MeshAgent C2 at 45.13.122.7 in July and 193.5.65.114 in September. Latter overlaps historical malicious workstation observations; BYOVD and recovery/log deletion observed.","Limitations":"Initial access unknown. MeshAgent is legitimate dual-use RMM; detection must correlate its server and behavior. Neither provider is labeled a bulletproof host by Huntress."},{"Source ID":"N42","Publisher":"Spamhaus","Title":"Botnet Threat Update January to June 2026","Published / Updated":"2026-07-10","URL":"https://www.spamhaus.org/resource-hub/botnet-c-c/botnet-threat-update-january-to-june-2026/","Source Type":"Primary anti-abuse report","Supports":"H1 botnet C2 counts: Stark 931 newly observed; Cloudzy 291 new/24 active; Virtualine 382 new/16 active; AS210558 273 new; AS214351 17 active. Other newly prominent networks include GlobalTeleHost and Ghosty Networks.","Limitations":"Counts are not sign-in attack probabilities and are not normalized by provider size. Newly observed ranking does not measure response speed. Hyperscaler presence does not establish BPH status."},{"Source ID":"N43","Publisher":"U.S. Department of the Treasury","Title":"United States, Australia, and United Kingdom Sanction Russian Cybercrime Infrastructure Supporting Ransomware","Published / Updated":"2025-11-19","URL":"https://home.treasury.gov/news/press-releases/sb0319","Source Type":"Official sanctions designation","Supports":"Direct official designation of Media Land and ML Cloud; Yalishanda alias; Aeza front Hypercore and sanctions-evasion entities Smart Digital Ideas DOO and Datavice MCHJ.","Limitations":"Designated legal entity is not automatically every rented upstream ASN. Requires legal/entity verification and current designation checking before sanctions enforcement."},{"Source ID":"N44","Publisher":"U.S. Department of the Treasury","Title":"Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against Americans","Published / Updated":"2026-07-13","URL":"https://home.treasury.gov/news/press-releases/sb0559","Source Type":"Official sanctions designation","Supports":"First VPN Service (1VPNS) and Dmytro Rashevskyi designated; service used for origin concealment, malware deployment, and exfiltration, after May 2026 infrastructure takedown.","Limitations":"1VPNS rents infrastructure under false identities. Sanctioned VPN reseller does not make its unrelated underlying hosting companies sanctioned. No exact ASN is designated here."},{"Source ID":"N45","Publisher":"FBI","Title":"First VPN Service Used by Ransomware Actors to Compromise Systems","Published / Updated":"2026-05-21","URL":"https://www.ic3.gov/CSA/2026/260521.pdf","Source Type":"Official FBI FLASH with IOCs","Supports":"33 IPs labeled current as of May 2026, an older historical IP set, four service domains. At least 25 ransomware groups used it; ATT&CK T1090, T1133, T1078, T1046, T1018, T1110.","Limitations":"FBI expressly warns that ephemeral cloud IPs may be reassigned and require current corroboration. Similar-named VPN services are excluded. May-era exit list is historical in September."},{"Source ID":"N46","Publisher":"Spamhaus","Title":"Bulletproof Hosting: Cutting off the facilitators","Published / Updated":"2026-06-11","URL":"https://www.spamhaus.org/resource-hub/bulletproof-hosting/bulletproof-hosting-cutting-off-the-facilitators/","Source Type":"Primary anti-abuse methodology","Supports":"Facilitator/transit role distinctions; IP leasing, shell entities, decoy ISPs and remote DDoS-protection topology; SBL escalations and response-based reputation.","Limitations":"No named ASN in article. Use to improve methodology and collateral-risk controls, not as evidence to add a specific ASN."},{"Source ID":"N47","Publisher":"Cisco Talos","Title":"Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use","Published / Updated":"2026-09-17","URL":"https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/","Source Type":"Primary vendor investigation","Supports":"Open-directory attack platform, VPN/tunneling, valid credentials and NTLM relay, AdaptixC2, rclone-to-Wasabi exfiltration.","Limitations":"No exact public IP/ASN in extracted text. Russian-language attribution is suggestive. Wasabi and dual-use tools are not malicious providers; no ASN addition justified."},{"Source ID":"N48","Publisher":"eSentire","Title":"GhostCode: Dissecting a Novel Device Code Phishing Kit","Published / Updated":"2026-09-15","URL":"https://www.esentire.com/blog/ghostcode-dissecting-a-novel-device-code-phishing-kit","Source Type":"Primary incident research with vendor IOC repository","Supports":"Device-code token theft; residential proxy rotation; GHOSTnet AS12586 enrollment.","Limitations":"Single observed incident. Residential addresses may be dynamic. Microsoft broker/resource IDs and scripting user agents are legitimate; correlate behavior. Source timestamp example has a weekday/date inconsistency, so use month-level observation scope."},{"Source ID":"N49","Publisher":"eSentire","Title":"GhostCode published IOC list","Published / Updated":"2026-09-15","URL":"https://github.com/eSentire/iocs/blob/main/GhostCode/GhostCode-iocs-09-09-2026.txt","Source Type":"Vendor-owned IOC repository","Supports":"Exact domains, IPs, hashes and kit artifacts.","Limitations":"Lookalike domains are marked possible relations; compromised-site indicators should remain subdomain scoped."},{"Source ID":"N50","Publisher":"Microsoft","Title":"Unmasking EvilTokens: Getting to the root of device code phishing","Published / Updated":"2026-09-22","URL":"https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/","Source Type":"Primary identity threat research","Supports":"Storm-2992 device-code abuse; Graph/inbox-rule and rogue-device persistence correlation.","Limitations":"No exact malicious IPs or new Clouvider/PacketHub attribution. Cloud platforms named are shared infrastructure, not malicious domains. A linked actor-profile label says Storm-2922 while narrative says Storm-2992; retain narrative attribution with discrepancy."},{"Source ID":"N51","Publisher":"Microsoft DCU","Title":"Disrupting EvilTokens: The AI Chatbot Built for Cybercrime","Published / Updated":"2026-09-22","URL":"https://blogs.microsoft.com/on-the-issues/2026/09/22/disrupting-eviltokens-the-ai-chatbot-built-for-cybercrime/","Source Type":"Primary disruption announcement","Supports":"50 websites seized, over 150 additional domains disabled; account compromise and BEC.","Limitations":"Disruption does not prove all affiliates stopped; no literal IOC list in announcement."},{"Source ID":"N52","Publisher":"Microsoft","Title":"Storm-3168: Agentic-driven cloud attacks using compromised service principals","Published / Updated":"2026-09-25","URL":"https://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/","Source Type":"Primary cloud intrusion research with exact IPs","Supports":"Compromised service principals; ARM enumeration, resource deletion, recovery-lock deletion attempts and ListKeys.","Limitations":"Initial access unclear; exposed GitHub secret not confirmed used. No ransom note or successful exfiltration confirmed. Source gives no ASNs."},{"Source ID":"N53","Publisher":"Microsoft DART","Title":"Beyond source code: A path to the keys to the kingdom","Published / Updated":"2026-09-29","URL":"https://www.microsoft.com/en-us/security/blog/2026/09/29/beyond-source-code-a-path-to-the-keys-to-the-kingdom/","Source Type":"Primary incident response case study","Supports":"Storm-3068 SSPR/auth-method takeover; Azure DevOps pipeline credential harvesting; kubeconfig, Atera and Chisel.","Limitations":"No precise infrastructure IOC or ASN in blog. Do not infer vulnerability exploitation from valid-identity abuse."},{"Source ID":"N54","Publisher":"Kaspersky GERT","Title":"Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO","Published / Updated":"2026-09-21","URL":"https://securelist.com/tr/payload-ransomware-via-group-policy/121335/","Source Type":"Primary incident response research with exact IOCs","Supports":"Valid compromised FortiGate SSL VPN credentials followed by malicious domain-root GPOs and extortion.","Limitations":"Credential theft method, lateral movement and IP roles not determined due logging gaps. No ASNs supplied; no live C2 confirmed. Windows impact occurred without encryption."},{"Source ID":"N55","Publisher":"Microsoft","Title":"Star Blizzard refines phishing and malware delivery with the RedFlick technique","Published / Updated":"2026-09-29","URL":"https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/","Source Type":"Primary threat research with exact IOCs","Supports":"Updated phishing/malware delivery infrastructure and CosmicPulse downloader indicators.","Limitations":"Mostly historical delivery infrastructure, not cloud sign-in source evidence. No ASNs supplied."},{"Source ID":"N56","Publisher":"Microsoft","Title":"Beyond the ransomware: Tracking Storm-2570's consistent tradecraft across deployments","Published / Updated":"2026-09-24","URL":"https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/","Source Type":"Primary ransomware tradecraft research","Supports":"RMM, credential access, tunnels and cloud exfiltration across Qilin/DragonForce/Anubis/BERT.","Limitations":"Initial access unconfirmed; no exact network indicators or provider ASN evidence extracted."},{"Source ID":"N57","Publisher":"Proofpoint","Title":"Spraying in the Andes: TeamFiltration Returns to Exploit Forgotten Service Accounts","Published / Updated":"2026-09-22","URL":"https://www.proofpoint.com/us/blog/threat-insight/Spraying-in-the-Andes-TeamFiltration-Returns","Source Type":"Primary identity threat research with exact infrastructure","Supports":"UNK_CondorFiltration password spraying against dormant service accounts, AWS EC2 source ranges, post-access VPN pivot, and stale TeamFiltration user-agent behavior.","Limitations":"AWS and DataCamp/CDN77 are shared infrastructure. Use the exact ranges, stale user agent, dormant-account pattern, failed-to-success sequence, and rapid ASN switch together; do not block the providers wholesale."},{"Source ID":"N58","Publisher":"Huntress","Title":"Railway PaaS abused in Microsoft 365 token replay campaign","Published / Updated":"2026-03-23","URL":"https://www.huntress.com/blog/railway-paas-m365-token-replay-campaign","Source Type":"Primary identity threat research with exact infrastructure","Supports":"Device-code phishing and token replay from Railway ranges 162.220.232.0/22 and 162.220.234.0/22; 162.220.234.41 dominant.","Limitations":"Railway is a legitimate PaaS. Use the ranges with device-code and token-replay behavior, not ASN-wide."},{"Source ID":"N59","Publisher":"Microsoft","Title":"AI-enabled device code phishing campaign","Published / Updated":"2026-04-06","URL":"https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/","Source Type":"Primary identity threat research with exact infrastructure","Supports":"Railway and HZ Hosting ranges listed as threat actor infrastructure observed with sign-in.","Limitations":"Ranges given as network addresses without length. Shared hosting; correlate with device-code flow."},{"Source ID":"N60","Publisher":"GreyNoise","Title":"Hidden pattern in credential-based attacks on Palo Alto and SonicWall","Published / Updated":"2025-12-04","URL":"https://www.greynoise.io/blog/hidden-pattern-credential-based-attacks-palo-alto-sonicwall","Source Type":"Primary vendor telemetry","Supports":"AS43350, AS215929, AS209588 and AS211632 carried most GlobalProtect login brute force, late September to mid-October 2025.","Limitations":"GreyNoise notes these ASNs are not generally associated with malicious infrastructure."},{"Source ID":"N61","Publisher":"Check Point Research","Title":"Iran-nexus password spray campaign targeting cloud environments with a focus on the Middle East","Published / Updated":"2026-03-31","URL":"https://blog.checkpoint.com/research/iran-nexus-password-spray-campaign-targeting-cloud-environments-with-a-focus-on-the-middle-east/","Source Type":"Primary identity threat research","Supports":"Microsoft 365 password spray via commercial VPN nodes at AS35758 (Windscribe, NordVPN ranges); Tor for scanning.","Limitations":"Commercial VPN exits are shared by many legitimate users."},{"Source ID":"N62","Publisher":"FBI and US Secret Service","Title":"FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts (JCSA-20261006-01)","Published / Updated":"2026-10-06","URL":"https://www.ic3.gov/CSA/2026/261006.pdf","Source Type":"Official joint cybersecurity advisory with IOCs","Supports":"13 IPs conducting FortiGate brute force or authenticating with compromised accounts, June to July 2026; C2, proxy, relay and Hashtopolis hosts.","Limitations":"The agencies warn the addresses may be reassigned and should be treated as historical within the activity window. ASNs are RIPEstat mappings, not stated in the advisory."},{"Source ID":"N63","Publisher":"Huntress","Title":"Two INC ransom notes","Published / Updated":"2026-09-21","URL":"https://www.huntress.com/blog/two-inc-ransom-notes","Source Type":"Primary vendor incident research","Supports":"AnyDesk C2 at 213.111.185.108 and PowerShell implant C2 domain throughoutes.net in an INC ransomware intrusion, August 2026.","Limitations":"Initial access vector not determined. Endpoint C2, not sign-in source evidence."},{"Source ID":"N64","Publisher":"Netify","Title":"DataCamp hosting profile","Published / Updated":"2026-10-07","URL":"https://www.netify.ai/resources/hosting/datacamp","Source Type":"Hosting and application classification","Supports":"VPN services (Hotspot Shield, generic VPN) and Tor observed hosted on DataCamp (AS212238).","Limitations":"Undated profile, retrieved 2026-10-07. Shows hosted services, not abuse."}]}
